Langflow Unauth RCE
Critical severity
GitHub Reviewed
Published
Jun 17, 2025
in
langflow-ai/langflow
•
Updated Jun 17, 2025
Description
Published to the GitHub Advisory Database
Jun 17, 2025
Reviewed
Jun 17, 2025
Last updated
Jun 17, 2025
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
References