<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Langflow</title><description>Vulnerabilities in Langflow, the open-source visual LLM-workflow builder — unauthenticated code-execution flaws, IDORs, and CORS bugs that keep landing on CISA&apos;s Known Exploited Vulnerabilities catalog as public-facing deployments get hit. Combined article + CVE feed for the Langflow beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2025-3248 — Langflow unauthenticated code injection in validate/code endpoint</title><link>https://0daynews.com/cve/cve-2025-3248/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-3248/</guid><description>Langflow &lt; 1.3.0: unauthenticated code injection allows RCE via crafted HTTP requests to /api/v1/validate/code. CVSS 9.8 critical. CISA KEV 2025-05-05.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate><category>Langflow</category><category>critical</category><category>cve</category></item><item><title>CVE-2025-34291 — Langflow CORS misconfiguration enables CSRF-driven token theft and RCE</title><link>https://0daynews.com/cve/cve-2025-34291/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-34291/</guid><description>Langflow ≤ 1.6.9: permissive CORS and SameSite=None cookies enable CSRF token theft, giving attackers RCE via authenticated endpoints. CVSS 8.8 high. CISA KEV 2026-05-21.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate><category>Langflow</category><category>high</category><category>cve</category></item><item><title>CVE-2026-0770 — Langflow validate-endpoint exec_globals RCE (unauthenticated)</title><link>https://0daynews.com/cve/cve-2026-0770/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-0770/</guid><description>Unauthenticated RCE in Langflow&apos;s /api/v1/validate endpoint via the exec_globals parameter. CISA added to KEV on 2026-07-21 with a federal patch deadline of 2026-07-24.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate><category>Langflow</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-33017 — Langflow public flow build endpoint allows unauthenticated RCE</title><link>https://0daynews.com/cve/cve-2026-33017/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-33017/</guid><description>Langflow &lt; 1.9.0: public flow build endpoint accepts attacker-supplied Python code passed to exec() with no sandboxing — unauthenticated RCE. CVSS 9.8 critical.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate><category>Langflow</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-55255 — Langflow /api/v1/responses IDOR — cross-user flow execution</title><link>https://0daynews.com/cve/cve-2026-55255/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-55255/</guid><description>An authenticated IDOR in Langflow&apos;s /api/v1/responses endpoint lets a logged-in attacker execute any other user&apos;s flow by passing the victim&apos;s flow UUID. NVD scores it 8.4 high; the vendor GHSA calls it 9.9 critical. Fixed in Langflow 1.9.1. Added to CISA KEV on 2026-07-07.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate><category>Langflow</category><category>high</category><category>cve</category></item><item><title>Public PoC Lands for Langflow&apos;s 9.8 Unauth RCE — Patch to 1.10.1 Now</title><link>https://0daynews.com/articles/2026-08-07-langflow-cve-2026-9198-unauth-rce-public-poc/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-07-langflow-cve-2026-9198-unauth-rce-public-poc/</guid><description>CVE-2026-9198 lets an unauthenticated network caller reach full remote code execution on default Langflow deployments. It&apos;s on CISA&apos;s KEV list, it&apos;s exploited, and a public proof-of-concept is now out.</description><pubDate>Fri, 07 Aug 2026 18:20:00 GMT</pubDate><category>Langflow</category><category>article</category></item><item><title>Langflow&apos;s fifth KEV entry: CVE-2026-0770, patch by Friday</title><link>https://0daynews.com/articles/2026-07-22-langflow-cve-2026-0770-fifth-kev-entry-federal-friday/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-22-langflow-cve-2026-0770-fifth-kev-entry-federal-friday/</guid><description>CISA added Langflow&apos;s unauthenticated RCE flaw CVE-2026-0770 to KEV on 2026-07-21 with a federal deadline of 2026-07-24. Fifth Langflow entry on the catalog in fourteen months — upgrade past 1.7.3.</description><pubDate>Wed, 22 Jul 2026 13:20:00 GMT</pubDate><category>Langflow</category><category>article</category></item></channel></rss>