Vulnerability record · CVE-2024-37014 · published 10 June 2024
CVE-2024-37014: Langflow custom_component endpoint allows remote code execution
Langflow · Langflow
Langflow through 0.6.19 exposes the POST /api/v1/custom_component endpoint, which accepts a user-supplied Python script and executes it. Because the endpoint is reachable without authentication, any untrusted user who can reach it can run arbitrary code on the server. The flaw is a code injection issue (CWE-94) with a critical CVSS score of 9.8.
Description
Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS score of 9.8 and a high EPSS probability makes this an urgent patching and exposure-reduction priority.
What it is
Langflow through 0.6.19 exposes the POST /api/v1/custom_component endpoint, which accepts a user-supplied Python script and executes it. Because the endpoint is reachable without authentication, any untrusted user who can reach it can run arbitrary code on the server. The flaw is a code injection issue (CWE-94) with a critical CVSS score of 9.8.
Impact
An attacker gains remote code execution on the Langflow host with the privileges of the Langflow process, allowing full compromise of confidentiality, integrity and availability. This can lead to data theft, service takeover and use of the host as a pivot point.
Attack surface
The flaw is reached over the network via the POST /api/v1/custom_component HTTP endpoint. The CVSS vector shows no privileges required and no user interaction, so any client that can reach the service can attempt it.
Exploitation
No CISA KEV listing and no ransomware usage are recorded, but the EPSS probability is 0.63 (99th percentile) and the only references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Langflow to a version later than 0.6.19 as soon as a fixed release is available.
- Restrict network access to the Langflow API so only trusted clients can reach /api/v1/custom_component.
- Require authentication and authorization on the custom component endpoint if the deployment cannot be patched immediately.
- Run Langflow with least privilege and isolate it from sensitive internal networks and data.
- Monitor and block requests that submit Python code to the custom component endpoint.
Detection
- Alert on POST requests to /api/v1/custom_component, especially from unexpected source IPs.
- Inspect request bodies for Python code patterns such as import, exec, eval or os.system.
- Monitor Langflow process behavior for unexpected child processes or outbound network connections.
- Review Langflow logs for custom component creation events that were not initiated by known administrators.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/langflow-ai/langflow/issues/1973 | ExploitIssue Tracking |
| https://github.com/langflow-ai/langflow/issues/1973 | ExploitIssue Tracking |
Track CVE-2024-37014 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-37014), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.