Safety vulnerability ID: 71781
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of Langflow allow remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.
Latest version: 1.1.3
A Python package with a built-in web application
Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script. See CVE-2024-37014.
MISC:https://github.com/langflow-ai/langflow/issues/1973: https://github.com/langflow-ai/langflow/issues/1973
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application