Intel

AIKIDO-2026-438566

langflow is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)GHSA-j8f7-x8jm-wmm4 Published Today

63

Medium Risk

This Affects:

PYTHONlangflow
1.0.0 - 1.10.2
Fixed in 1.10.3
Are you affected? Scan for Free

TL;DR

RSS Reader, SearXNG, Web Search, Home Assistant, Glean, and Docling Serve send HTTP requests to a URL taken from the flow, and the SSRF guard is either off by default or not used by those components. A signed-in user who can build a flow can point a component at a loopback, private, or metadata address and read the response. The fix checks each URL after DNS resolution, pins that address, and blocks private, loopback, link local, and metadata targets unless the host is allowlisted.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and signed-in users can run flows whose components fetch a URL.

Background info

langflow is vulnerable to Server-Side Request Forgery (SSRF) in versions 1.0.0 - 1.10.2.

How to fix this

Upgrade the langflow library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform