CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[UPDATE] [hoch] Langflow OSS: Mehrere Schwachstellen

highCVE-2026-12763CVE-2026-12765CVE-2026-12766CVE-2026-17631CVE-2026-19298CVE-2026-19299
Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Langflow OSS ausnutzen, um Sicherheitsmaßnahmen zu umgehen, beliebigen Code auszuführen, Server-Side Request Forgery (SSRF) durchzuführen, sensible Daten offenzulegen oder zu manipulieren oder Cross-Site-Scripting-Angriffe durchzuführen.

CSIRTS triage

What
Multiple critical vulnerabilities including arbitrary code execution, SSRF, privilege bypass, and cross-site scripting in Langflow OSS.
Who is affected
Authenticated users and potentially anonymous attackers on exposed Langflow OSS instances.
Urgency
High; remote code execution vulnerability with multiple attack vectors makes this urgent for internet-facing deployments.
Action
Immediately apply available patches or upgrade to latest Langflow OSS version; restrict network access until patched.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Langflow OSS

Get an email when a new Langflow OSS advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
high
Published
2026-09-07
Exploitation
Not in CISA KEV at last sync

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3096

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-12763coverage & exploitation statusNVD · CVE.org
CVE-2026-12765coverage & exploitation statusNVD · CVE.org
CVE-2026-12766coverage & exploitation statusNVD · CVE.org
CVE-2026-17631coverage & exploitation statusNVD · CVE.org
CVE-2026-19298coverage & exploitation statusNVD · CVE.org
CVE-2026-19299coverage & exploitation statusNVD · CVE.org
CVE-2026-19300coverage & exploitation statusNVD · CVE.org
CVE-2026-19301coverage & exploitation statusNVD · CVE.org
CVE-2026-19302coverage & exploitation statusNVD · CVE.org
CVE-2026-19303coverage & exploitation statusNVD · CVE.org
CVE-2026-19304coverage & exploitation statusNVD · CVE.org
CVE-2026-19305coverage & exploitation statusNVD · CVE.org
CVE-2026-19306coverage & exploitation statusNVD · CVE.org
CVE-2026-8447coverage & exploitation statusNVD · CVE.org
CVE-2026-9138coverage & exploitation statusNVD · CVE.org
CVE-2026-9186coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Langflow OSS

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories