{"api_version":"v1","generated_at":"2026-10-08T10:40:00+00:00","product":{"cve_count":39,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-langflow-ai-langflow-0c2305f52759","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/langflow","name":"langflow","next_cursor":null,"observations":[{"affected":"langflow: >= 1.5.0, < 1.10.3","affected_versions_present":true,"cve_id":"CVE-2026-105741","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-105741","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-06T16:43:02.046Z","patch_url":"","primary_source":"","published":"2026-10-05T20:56:00.060Z"},{"affected":"langflow: < 1.9.0","affected_versions_present":true,"cve_id":"CVE-2026-105740","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-105740","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-06T18:20:28.495Z","patch_url":"","primary_source":"","published":"2026-10-05T20:46:18.854Z"},{"affected":"langflow: >= 1.6.8, <= 1.9.0","affected_versions_present":true,"cve_id":"CVE-2026-105699","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-105699","fixed":"1.9.1.","last_modified":"2026-10-08T02:26:48.618Z","patch_url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-4hmc-cfm3-w43c","primary_source":"","published":"2026-10-05T20:37:59.630Z"},{"affected":"langflow: >= 1.0.0, < 1.10.1; langflow-base: < 0.10.1","affected_versions_present":true,"cve_id":"CVE-2026-105698","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-105698","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-06T13:58:36.614Z","patch_url":"","primary_source":"","published":"2026-10-05T20:20:27.287Z"},{"affected":"langflow: >= 1.1.2, < 1.10.3; langflow-base: >= 0.1.2, < 0.10.3; lfx: < 1.10.3","affected_versions_present":true,"cve_id":"CVE-2026-105697","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-105697","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-06T14:49:22.922Z","patch_url":"","primary_source":"","published":"2026-10-05T20:16:58.291Z"},{"affected":"langflow: 1.0.16 < 1.12.0, 0.0.94 < 1.12.0","affected_versions_present":true,"cve_id":"CVE-2026-101861","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-101861","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-01T15:19:46.570Z","patch_url":"","primary_source":"","published":"2026-09-28T15:49:14.349Z"},{"affected":"< 1.10.0","affected_versions_present":true,"cve_id":"CVE-2026-48520","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48520","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-24T14:19:11.074Z","patch_url":"","primary_source":"","published":"2026-06-23T16:31:27.362Z"},{"affected":"< 1.9.0","affected_versions_present":true,"cve_id":"CVE-2026-33760","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33760","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-24T15:47:28.163Z","patch_url":"","primary_source":"","published":"2026-06-23T16:30:16.819Z"},{"affected":"< 1.9.0","affected_versions_present":true,"cve_id":"CVE-2026-42867","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42867","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-23T17:02:43.824Z","patch_url":"https://github.com/langflow-ai/langflow/pull/12337","primary_source":"","published":"2026-06-23T16:29:11.848Z"},{"affected":"< 1.7.0","affected_versions_present":true,"cve_id":"CVE-2026-55423","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55423","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-23T17:07:10.031Z","patch_url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-7hw8-6q6r-4276","primary_source":"","published":"2026-06-23T16:27:19.134Z"},{"affected":"< 1.0.19","affected_versions_present":true,"cve_id":"CVE-2026-55446","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55446","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-23T17:56:37.766Z","patch_url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-qwqc-p3q8-wcg9","primary_source":"","published":"2026-06-23T16:26:17.990Z"},{"affected":"< 1.9.2","affected_versions_present":true,"cve_id":"CVE-2026-48519","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48519","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-24T03:56:21.994Z","patch_url":"","primary_source":"","published":"2026-06-23T16:25:09.927Z"},{"affected":"< 1.9.2","affected_versions_present":true,"cve_id":"CVE-2026-55447","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55447","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-24T15:47:39.931Z","patch_url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-ccv6-r384-xp75","primary_source":"","published":"2026-06-23T16:21:42.570Z"},{"affected":"< 1.9.1","affected_versions_present":true,"cve_id":"CVE-2026-55450","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55450","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-23T17:02:55.053Z","patch_url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-x223-p2gf-v735","primary_source":"","published":"2026-06-23T16:17:52.168Z"},{"affected":"1.9.0; 1.9.1; 1.9.2; 1.9.3","affected_versions_present":true,"cve_id":"CVE-2026-12822","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-12822","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-23T13:39:24.719Z","patch_url":"https://github.com/dxz0069/softwareoverflow/blob/main/langflow_bundle_url_custom_component_startup_rce_vulndb.md","primary_source":"","published":"2026-06-21T23:30:09.211Z"},{"affected":"< 1.9.0","affected_versions_present":true,"cve_id":"CVE-2026-42048","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42048","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-13T14:14:16.193Z","patch_url":"","primary_source":"","published":"2026-05-12T17:35:27.688Z"},{"affected":"langflow: 1.10.0, 1.10.1, 1.10.2","affected_versions_present":true,"cve_id":"CVE-2026-7700","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-7700","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-06T05:35:31.424Z","patch_url":"","primary_source":"","published":"2026-05-03T14:15:15.887Z"},{"affected":"1.8.0; 1.8.1; 1.8.2; 1.8.3; 1.8.4","affected_versions_present":true,"cve_id":"CVE-2026-7687","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-7687","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-05T00:40:09.897Z","patch_url":"","primary_source":"","published":"2026-05-03T08:45:14.754Z"},{"affected":"1.8.0; 1.8.1; 1.8.2; 1.8.3","affected_versions_present":true,"cve_id":"CVE-2026-6600","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-6600","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-20T14:54:42.453Z","patch_url":"","primary_source":"","published":"2026-04-20T03:15:12.169Z"},{"affected":"1.8.0; 1.8.1; 1.8.2; 1.8.3","affected_versions_present":true,"cve_id":"CVE-2026-6599","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-6599","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-20T14:24:36.870Z","patch_url":"","primary_source":"","published":"2026-04-20T03:00:15.645Z"},{"affected":"1.8.0; 1.8.1; 1.8.2; 1.8.3","affected_versions_present":true,"cve_id":"CVE-2026-6598","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-6598","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-20T16:19:18.233Z","patch_url":"","primary_source":"","published":"2026-04-20T02:45:15.874Z"},{"affected":"1.8.0; 1.8.1; 1.8.2; 1.8.3","affected_versions_present":true,"cve_id":"CVE-2026-6597","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-6597","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-20T11:42:32.582Z","patch_url":"","primary_source":"","published":"2026-04-20T02:30:14.803Z"},{"affected":"1.0; 1.1.0","affected_versions_present":true,"cve_id":"CVE-2026-6596","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-6596","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-20T14:54:40.530Z","patch_url":"","primary_source":"","published":"2026-04-20T02:15:13.863Z"},{"affected":"< 1.5.1; < 0.5.1","affected_versions_present":true,"cve_id":"CVE-2026-34046","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34046","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-01T03:55:31.834Z","patch_url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-8c4j-f57c-35cf","primary_source":"","published":"2026-03-27T20:06:35.836Z"},{"affected":"< 1.9.0","affected_versions_present":true,"cve_id":"CVE-2026-33873","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33873","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-02T13:03:34.809Z","patch_url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-v8hw-mh8c-jxfc","primary_source":"","published":"2026-03-27T20:04:23.646Z"},{"affected":"version range in vendor record","affected_versions_present":true,"cve_id":"CVE-2026-5027","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-5027","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-27T15:11:42.918Z","patch_url":"","primary_source":"","published":"2026-03-27T14:54:53.609Z"},{"affected":"version range in vendor record","affected_versions_present":true,"cve_id":"CVE-2026-5026","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-5026","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-27T15:35:23.336Z","patch_url":"","primary_source":"","published":"2026-03-27T14:50:36.603Z"},{"affected":"version range in vendor record","affected_versions_present":true,"cve_id":"CVE-2026-5025","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-5025","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-27T15:38:54.925Z","patch_url":"","primary_source":"","published":"2026-03-27T14:43:00.533Z"},{"affected":"version range in vendor record","affected_versions_present":true,"cve_id":"CVE-2026-5022","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-5022","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-27T15:10:20.925Z","patch_url":"","primary_source":"","published":"2026-03-27T14:34:14.046Z"},{"affected":"< 1.7.1","affected_versions_present":true,"cve_id":"CVE-2026-33497","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33497","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-24T17:45:26.314Z","patch_url":"","primary_source":"","published":"2026-03-24T13:14:39.647Z"},{"affected":">= 1.0.0, < 1.9.0","affected_versions_present":true,"cve_id":"CVE-2026-33484","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33484","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-24T13:37:14.286Z","patch_url":"","primary_source":"","published":"2026-03-24T12:57:33.641Z"},{"affected":"< 1.9.0","affected_versions_present":true,"cve_id":"CVE-2026-33475","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33475","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-25T03:55:45.997Z","patch_url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-87cc-65ph-2j4w","primary_source":"","published":"2026-03-24T12:54:33.369Z"},{"affected":">= 1.2.0, < 1.9.0","affected_versions_present":true,"cve_id":"CVE-2026-33309","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33309","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-25T03:55:47.098Z","patch_url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-g2j9-7rj2-gm6c","primary_source":"","published":"2026-03-24T12:49:16.276Z"},{"affected":"< 1.9.0","affected_versions_present":true,"cve_id":"CVE-2026-33053","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33053","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-20T18:07:41.668Z","patch_url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-rf6x-r45m-xv3w","primary_source":"","published":"2026-03-20T06:53:48.471Z"},{"affected":"< 1.8.0","affected_versions_present":true,"cve_id":"CVE-2026-27966","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-27966","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-28T04:55:26.622Z","patch_url":"https://github.com/langflow-ai/langflow/commit/d8c6480daa17b2f2af0b5470cdf5c3d28dc9e508","primary_source":"","published":"2026-02-26T01:55:18.580Z"},{"affected":"< 1.7.0.dev45","affected_versions_present":true,"cve_id":"CVE-2026-21445","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-21445","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-26T15:04:59.539Z","patch_url":"https://github.com/langflow-ai/langflow/commit/3fed9fe1b5658f2c8656dbd73508e113a96e486a","primary_source":"","published":"2026-01-02T19:11:24.451Z"},{"affected":"< 1.7.0","affected_versions_present":true,"cve_id":"CVE-2025-68478","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68478","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-12-19T17:59:42.829Z","patch_url":"","primary_source":"","published":"2025-12-19T17:10:14.107Z"},{"affected":"< 1.7.0","affected_versions_present":true,"cve_id":"CVE-2025-68477","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68477","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-12-19T17:59:55.722Z","patch_url":"","primary_source":"","published":"2025-12-19T16:43:00.551Z"},{"affected":"<= 1.5.0","affected_versions_present":true,"cve_id":"CVE-2025-57760","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-57760","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-08-25T20:34:14.809Z","patch_url":"https://github.com/langflow-ai/langflow/commit/c188ec113c9ca46154ad01d0eded1754cc6bef97","primary_source":"","published":"2025-08-25T16:22:17.772Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"langflow-ai"}}
