← Vulnerability feed

Vulnerability record · CVE-2024-37014 · published 10 June 2024

CVE-2024-37014: Langflow custom_component endpoint allows remote code execution

Langflow · Langflow

Langflow through 0.6.19 exposes the POST /api/v1/custom_component endpoint, which accepts a user-supplied Python script and executes it. Because the endpoint is reachable without authentication, any untrusted user who can reach it can run arbitrary code on the server. The flaw is a code injection issue (CWE-94) with a critical CVSS score of 9.8.

9.8 CVSS 3.1 Critical EPSS 64% · top 0.8% CWE-94 · Code injection
9.8CVSS 3.1 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS score of 9.8 and a high EPSS probability makes this an urgent patching and exposure-reduction priority.

What it is

Langflow through 0.6.19 exposes the POST /api/v1/custom_component endpoint, which accepts a user-supplied Python script and executes it. Because the endpoint is reachable without authentication, any untrusted user who can reach it can run arbitrary code on the server. The flaw is a code injection issue (CWE-94) with a critical CVSS score of 9.8.

Impact

An attacker gains remote code execution on the Langflow host with the privileges of the Langflow process, allowing full compromise of confidentiality, integrity and availability. This can lead to data theft, service takeover and use of the host as a pivot point.

Attack surface

The flaw is reached over the network via the POST /api/v1/custom_component HTTP endpoint. The CVSS vector shows no privileges required and no user interaction, so any client that can reach the service can attempt it.

Exploitation

No CISA KEV listing and no ransomware usage are recorded, but the EPSS probability is 0.63 (99th percentile) and the only references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Langflow to a version later than 0.6.19 as soon as a fixed release is available.
  • Restrict network access to the Langflow API so only trusted clients can reach /api/v1/custom_component.
  • Require authentication and authorization on the custom component endpoint if the deployment cannot be patched immediately.
  • Run Langflow with least privilege and isolate it from sensitive internal networks and data.
  • Monitor and block requests that submit Python code to the custom component endpoint.

Detection

  • Alert on POST requests to /api/v1/custom_component, especially from unexpected source IPs.
  • Inspect request bodies for Python code patterns such as import, exec, eval or os.system.
  • Monitor Langflow process behavior for unexpected child processes or outbound network connections.
  • Review Langflow logs for custom component creation events that were not initiated by known administrators.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-37014 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-9198Langflow auto_login and code validation chain enables unauthenticated RCEIBM Langflow OSS 1.0.0 through 1.10.0 exposes /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, and /api/v1/validate/code, whic…KEVEPSS 29%analysed9.8CVE-2026-0770Langflow validate endpoint exec_globals remote code executionLangflow mishandles the exec_globals parameter passed to its validate endpoint, allowing functionality from an untrusted control sphere to be include…KEVEPSS 64%analysed9.8CVE-2025-3248Langflow unauthenticated code injection in validate/code endpointLangflow versions prior to 1.3.0 expose the /api/v1/validate/code endpoint without authentication, allowing code injection. A remote attacker can sen…KEVEPSS 100%analysed9.4CVE-2025-34291Langflow CORS misconfiguration leads to token theft and RCELangflow up to and including 1.6.9 ships an overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) and a refresh token …KEVEPSS 93%analysed9.3CVE-2026-33017Langflow build_public_tmp endpoint unauthenticated remote code executionLangflow versions prior to 1.9.0 expose the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint without authentication, and when the optional data …KEVEPSS 25%analysed8.4CVE-2026-55255Langflow IDOR in responses endpoint allows cross-user flow executionLangflow before 1.9.1 has an insecure direct object reference in the /api/v1/responses endpoint. An authenticated attacker can supply another user's …KEVEPSS 0.89%analysed10.0CVE-2026-10134Langflow code injection vulnerabilityIBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversat…EPSS 0.64%10.0CVE-2026-10561Langflow code injection vulnerabilityIBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass tha…EPSS 1.0%

Source: NIST National Vulnerability Database (record CVE-2024-37014), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.