Multiple security vulnerabilities affecting Langflow OSS versions All 25 flaws affect Langflow OSS 1 have been identified in Langflow OSS versions 1.0.0 through 1.12.2. These flaws can lead to unauthenticated code execution, sandbox escapes for logged-in users, file access and data leaks, and other issues. Affected versions include all of Langflow OSS 1.
CVE-2026-104334 (CVSS 9.8 — Critical): This vulnerability stems from improper control of code generation, allowing an unauthenticated attacker to run code.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting Langflow OSS versions All 25 flaws affect Langflow OSS 1 have been identified in Langflow OSS versions 1.0.0 through 1.12.2. These flaws can lead to unauthenticated code execution, sandbox escapes for logged-in users, file access and data leaks, and other issues. Affected versions include all of Langflow OSS 1.
CVE-2026-104334 (CVSS 9.8 — Critical): This vulnerability stems from improper control of code generation, allowing an unauthenticated attacker to run code.[emaillocker id="1283"]
CVE-2026-93674 (CVSS 9.8 — Critical): This flaw involves improper neutralization of special elements used in an OS command, also allowing an unauthenticated attacker to run code.
CVE-2026-93675 (CVSS 8.8 — High): This vulnerability abuses dependency confusion and requires no login, though a user must take an action.
CVE-2026-97655: This flaw slips past an incomplete blocklist in the code security scanner, bypassing platform security checks for authenticated users.
CVE-2026-97676: This vulnerability enables a sandbox escape for logged-in users.
CVE-2026-93447 (CVSS 8.5 — High): This bug abuses deserialization of cached Redis values and requires the server secret and Redis write access.
CVE-2026-97677: This flaw lets a flow author write files into any directory writable by the service account, potentially reading configuration files, secrets, or database files.
CVE-2026-93679: This bug crashes the server with oversized ZIP archives.
These vulnerabilities collectively present significant risks to Langflow users.
We recommend you to update Langflow to version 1.12.3.
The following reports contain further technical details:
[/emaillocker]