A critical vulnerability (CVSS 9.8) in Langflow allows an unauthenticated remote attacker to execute arbitrary code with administrator privileges. The flaw affects Langflow version 1.4.2, and a mitigation is available, though the article does not specify a fixed version number.
[WID-SEC-2026-3164] Langflow: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 9.4 (kritisch) Remoteangriff ja Datum 02.09.2026 Stand 03.09.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux MacOS X Sonstiges UNIX Windows Produktbeschreibung Langflow bietet eine visuelle Schnittstelle zum Erstellen von LLM-basierten Anwendungen. Produkte 02.09.2026 Open Source Langflow 1.4.2 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Langflow ausnutzen, um beliebigen Programmcode mit Administratorrechten auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben