PyPI: langflow
CVE-2024-37014
Safety vulnerability ID: SFTY-20240610-83586
Safety legacy ID: pyup.io-71781
Affected versions of Langflow allow remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.
Overview
Langflow remote code execution vulnerability
Advisory
Affected versions of Langflow allow remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.
How to Fix
Upgrade
langflow
to1.0.15
or higher.Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20240610-83586/CVE-2024-37014
- https://nvd.nist.gov/vuln/detail/CVE-2024-37014
- https://github.com/langflow-ai/langflow/issues/1973
- https://github.com/pypa/advisory-database/tree/main/vulns/langflow/PYSEC-2024-177.yaml
- https://github.com/advisories/GHSA-qg33-x2c5-6p44
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
