langflow is vulnerable to Remote Code Execution (RCE)
97
Critical Risk
The /api/v1/auto_login endpoint mints a SUPERUSER bearer token for any network caller when auto-login is enabled, and /api/v1/validate/code runs submitted Python through exec(), including decorators, default arguments, and annotations at definition time. An unauthenticated attacker can obtain that token and then submit code to the validation endpoint to execute arbitrary commands on the host. The fix removes this unauthenticated chain so default deployments no longer expose superuser token minting paired with remote code execution.
You are affected if you are using a version that falls within the vulnerable range and expose a default Langflow deployment with auto-login enabled.
langflow is vulnerable to Remote Code Execution (RCE) in versions 0.0.19 - 1.10.0.
Upgrade the langflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant