CVE-2024-7297: Langflow
High severity, CVSS 8.8. EPSS: 21.2% chance of exploitation in the next 30 days.
Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request on the '/api/v1/users' endpoint.
Affected products
- Langflow Langflow: before 1.0.13 (fixed in 1.0.13)
Published 2024-07-30. Last modified 2026-06-17.