These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-55255 is a critical vulnerability in Langflow, a tool for building and deploying AI-powered agents and workflows. The vulnerability is an Insecure Direct Object Reference (IDOR) in the /api/v1/responses endpoint, which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This vulnerability has a CVSS score of 9.9 and is [truncated]
CVE-2026-55450 is a critical vulnerability in Langflow, a tool for building and deploying AI-powered agents and workflows. Prior to version 1.9.1, the vulnerability allows unauthenticated users to upload any amount of data to the server without limitations, potentially leading to server space exhaustion. Additionally, the absolute path of the uploaded file is reported to the attacker in the response, whic [truncated]
CVE-2026-48520 is a medium-severity vulnerability in Langflow's AI-powered agents and workflows. The 'Shareable Playground' feature, also known as 'Public Flows', allows public execution of flows, which can lead to arbitrary file reads. An attacker can exploit this by making a flow public and including a list of files to be read by Langflow and fed into the LLM. The vulnerability is fixed in version 1.10. [truncated]
CVE-2026-42867 is a Path Traversal vulnerability in Langflow, a tool for building and deploying AI-powered agents and workflows. The vulnerability exists in the Knowledge Bases API (POST /api/v1/knowledge_bases) due to improper sanitization of user-supplied knowledge base names, allowing an authenticated attacker to create directories and write files anywhere on the server's filesystem. This issue is fixe [truncated]
CVE-2026-33760 is an IDOR/BOLA vulnerability in Langflow's /api/v1/monitor router. The vulnerability allows any authenticated user to read, modify, rename, or permanently delete another user's data by supplying the target's resource ID or flow_id. This issue was fixed in Langflow version 1.9.0. The vulnerability has a CVSS score of 8.8 and is classified as HIGH severity.
CVE-2026-12822 is a low-severity vulnerability in langflow-ai langflow up to 1.9.3. The issue affects an unknown function of the Bundle URL Loader component, allowing for code injection. The attack requires local access. The vendor, langflow-ai, was contacted but did not respond. Given the low CVSS score of 1.9, this issue has a relatively low priority posture. However, defenders should still assess their [truncated]