#LangFlow
langflow-ai / langflow

Langflow is a low-code app builder for RAG and multi-agent AI applications. It’s Python-based and agnostic to any model, API, or database.

https://github.com/langflow-ai/langflow
December 9, 2024 at 10:15 PM
𝗧𝗿𝗮𝗻𝘀𝗳𝗼𝗿𝗺 𝗔𝗜 𝗖𝗵𝗮𝘁 𝗥𝗲𝘀𝗽𝗼𝗻𝘀𝗲𝘀 𝗘𝗳𝗳𝗼𝗿𝘁𝗹𝗲𝘀𝘀𝗹𝘆!

𝗧𝗿𝗮𝗻𝘀𝗳𝗼𝗿𝗺 𝗔𝗜 𝗖𝗵𝗮𝘁 𝗥𝗲𝘀𝗽𝗼𝗻𝘀𝗲𝘀 𝗘𝗳𝗳𝗼𝗿𝘁𝗹𝗲𝘀𝘀𝗹𝘆!

Explore the powerful capabilities of Langflow, a cutting-edge framework designed for AI interactions.

#Langflow #AI #Nocode
September 25, 2026 at 1:12 PM
We are living in wild times.

github.com/langflow-ai/...
March 4, 2025 at 11:07 AM
🔥 Hot Repo! 🔥 (100+ new stars)

📦 langflow-ai / langflow
⭐ 36,399 (+145)
🗒 JavaScript

Langflow is a low-code app builder for RAG and multi-agent AI applications. It’s Python-based and agnostic to any model, API, or database.
GitHub - langflow-ai/langflow: Langflow is a low-code app builder for RAG and multi-agent AI applications. It’s Python-based and agnostic to any model, API, or database.
Langflow is a low-code app builder for RAG and multi-agent AI applications. It’s Python-based and agnostic to any model, API, or database. - langflow-ai/langflow
github.com
December 1, 2024 at 7:01 PM
Langflow's AI agent builder carries 39 CVEs, 1 in CISA KEV and 84% unpatched. Trust score D. Check before you deploy. https://www.valtersit.com/vendors/langflow/ #cybersecurity #infosec #Langflow
Langflow
www.valtersit.com
September 25, 2026 at 3:00 PM
ハッカーがLangflowとRuby on Railsの重大な脆弱性を悪用し、アクティブなリモートコード実行攻撃を実施

攻撃者は、LangflowとRuby on Railsに影響を与える、新たに明らかになった2つのリモートコード実行の脆弱性を積極的に悪用しています。これらの攻撃は、クラウド認証情報の窃盗、ホスト偵察、およびコマンド&コントロール(C2)機能の確立を主な目的としています。

VulnCheckの研究者らは、AIを活用したアプリケーションや自動化されたワークフローを構築するためのローコードプラットフォームであるLangflowのCVE-2026-0768を標的とした悪用事...
Hackers Exploit Critical Langflow and Ruby on Rails Flaws in Active RCE Attacks
Threat actors are actively exploiting a critical remote code execution vulnerability in Langflow, a low-code platform used for building AI-powered applications and automating workflows.
gbhackers.com
September 26, 2026 at 4:31 AM
Langflowの重大な脆弱性が悪用され、OpenAIとAWSの鍵が盗まれる

攻撃者は、AIアプリケーション構築のためのオープンソースフレームワークであるLangflowに存在する、認証不要のリモートコード実行の脆弱性(CVE-2026-0768)を悪用し、認証情報、トークン、および鍵を盗み出しています。

このセキュリティ問題は重大度「クリティカル」と評価され、Langflowのカスタムコンポーネントエディタのコードバリデーターに存在します。

脅威インテリジェンス企業のVulnCheckは、週末にかけて英国にある同社のハニーポットが少なくとも50件の攻撃の標的となり、攻撃トラフィッ...
Critical Langflow flaw exploited to steal OpenAI and AWS keys
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, an...
www.bleepingcomputer.com
September 26, 2026 at 4:35 AM
𝗦𝗲𝗮𝗺𝗹𝗲𝘀𝘀𝗹𝘆 𝗦𝘄𝗶𝘁𝗰𝗵 𝘁𝗼 𝗔𝗻𝘁𝗵𝗿𝗼𝗽𝗶𝗰 𝗶𝗻 𝗟𝗮𝗻𝗴𝗳𝗹𝗼𝘄!

Discover a straightforward method to switch AI models in Langflow, moving from OpenAI to Anthropic.

#Langflow #Anthropic #OpenAI #AI
September 24, 2026 at 1:08 PM
Langflow, low-code AI builder for agentic and RAG applications
Langflow | Low-code AI builder for agentic and RAG applications
Langflow is a low-code AI builder for agentic and retrieval-augmented generation (RAG) apps. Code in Python and use any LLM or vector database.
www.langflow.org
August 22, 2025 at 3:55 AM
🔥 Hot Repo! 🔥 (100+ new stars)

📦 langflow-ai / langflow
⭐ 23,618 (+152)
🗒 JavaScript

⛓️ Langflow is a visual framework for building multi-agent and RAG applications. It's open-source, Python-powered, fully customizable, model and vector store agnostic.
GitHub - langflow-ai/langflow: ⛓️ Langflow is a visual framework for building multi-agent and RAG applications. It's open-source, Python-powered, fully customizable, model and vector store agnostic.
⛓️ Langflow is a visual framework for building multi-agent and RAG applications. It's open-source, Python-powered, fully customizable, model and vector store agnostic. - langflow-ai/langflow
github.com
August 6, 2024 at 3:00 PM
Want to kick off 2025 building @bsky.app bots?

Here's a new blog post on how to build a GenAI bot using the fabulous @skyware.js.org library and Langflow.

www.datastax.com/blog/genai-b...
How to Build a GenAI Bluesky Bot with Langflow, TypeScript,and Node.js | DataStax
Learn how to build a small TypeScript application that creates a Bluesky bot powered by Langflow.
www.datastax.com
January 2, 2025 at 11:24 PM
🔦 Open-source tool of the day: Langflow

Langflow is a visual, Python-based builder for agentic and RAG applications, with a node canvas and an API to …
⚡ OSAI Pulse: 97/100

https://opensourceai.tech/tool/langflow.html

#OpenSource #AI #DevTools
Langflow
Visual builder for agents and RAG
opensourceai.tech
July 7, 2026 at 10:00 AM
A threat actor is hacking Langflow AI servers to deploy Flodrix, a DDoS botnet malware strain

www.trendmicro.com/en_us/resear...
June 17, 2025 at 4:10 PM
Threat actors are exploiting a vulnerability (CVE-2025-3248) disclosed last month to take over AI apps/servers that use the Langflow toolkit

Exploitation reported via CISA: www.cisa.gov/news-events/...

Original write-up by Horizon3: horizon3.ai/attack-resea...
Unsafe at Any Speed: Abusing Python Exec for Unauth RCE in Langflow AI
CVE-2025-3248 is a critical code injection vulnerability affecting Langflow, a popular tool used for building out agentic AI workflows. This vulnerability is easily exploitable and enables unauthentic...
horizon3.ai
May 6, 2025 at 10:20 AM
The Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are actively exploiting a critical vulnerability identified as CVE-2026-33017, which affects the Langflow framework for building AI agents.
CISA: New Langflow flaw actively exploited to hijack AI workflows
The Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are actively exploiting a critical vulnerability identified as CVE-2026-33017, which affects the Langflow framework for building AI agents.
www.bleepingcomputer.com
March 26, 2026 at 7:17 PM
Learn how to integrate the #Langflow API into your Node.js app with this step-by-step guide by @philna.sh 🚀 #genai

Full post: https://dev.to/datastax/how-to-use-the-langflow-api-in-nodejs-2a12
February 4, 2025 at 2:56 PM
🚀 𝗥𝗲𝘃𝗼𝗹𝘂𝘁𝗶𝗼𝗻𝗶𝘇𝗶𝗻𝗴 𝗔𝗜 𝗖𝗼𝗹𝗹𝗮𝗯𝗼𝗿𝗮𝘁𝗶𝗼𝗻: 𝗛𝗼𝘄 𝗟𝗮𝗻𝗴𝗳𝗹𝗼𝘄 𝟭.𝟭 𝗧𝗿𝗮𝗻𝘀𝗳𝗼𝗿𝗺𝘀 𝗠𝘂𝗹𝘁𝗶-𝗔𝗴𝗲𝗻𝘁 𝗦𝘆𝘀𝘁𝗲𝗺𝘀

👉 https://buff.ly/3D6NScK

#AIDevelopment #Langflow #AIInnovation #MultiAgentSystems
Revolutionizing AI Collaboration: How Langflow 1.1 Transforms Multi-Agent Systems
Explore how Langflow 1.1 revolutionizes AI multi-agent systems with enhanced agent creation, direct communication, and improved usability. Discover its impact on AI workflows.
buff.ly
December 8, 2024 at 9:12 PM
CVE-2026–17633 - Authenticated RCE in Langflow OSS via /api/v1/custom_component
## Summary Field | Value ---|--- CVE ID | CVE-2026-17633 CVSS | 8.5 (HIGH) CWE | CWE-94 (Improper Control of Generation of Code) Affected | Langflow OSS 1.0.0 – 1.10.3 Preconditions | Any authenticated user + `LANGFLOW_ALLOW_CUSTOM_COMPONENTS=true` Vulnerable endpoint | `POST /api/v1/custom_component` Langflow is an open-source low-code platform for building LLM applications and agent workflows visually. One of its features, **Custom Components** , lets users define a component's behavior directly in Python. That feature is the attack surface for this vulnerability. IBM's security advisory (published August 5, 2026) disclosed a cluster of issues in Langflow OSS 1.0.0–1.10.3. CVE-2026–17633 is the authenticated RCE reachable through `/api/v1/custom_component`. ## Root Cause - Source-Level Analysis ### 1.1 The vulnerable endpoint From `langflow/api/v1/endpoints.py` (around line 1271): @router.post("/custom_component", status_code=HTTPStatus.OK, include_in_schema=False) async def custom_component(  raw_code: CustomComponentRequest,  user: CurrentActiveUser,  request: Request, ) -> CustomComponentResponse:  …  # The only gate: "is the custom-component feature enabled at all?"  if not settings.allow_custom_components and not code_hash_matches_any_template(raw_code.code, all_known):  raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, …) # scan_code_security() is never called here  component = Component(_code=effective_code)  built_frontend_node, component_instance = build_custom_component_template(component, user_id=user.id) The important detail isn't that there's "no validation" - it's that the validation checks the wrong thing. `allow_custom_components` answers "is this user allowed to create custom components," not "is this code's content safe." In production, `LANGFLOW_ALLOW_CUSTOM_COMPONENTS=true` is a common setting, and once it's on, this check passes trivially and the code flows through with zero content inspection. Langflow does ship a separate AST-based scanner, `scan_code_security()` (covered in section 5), but this endpoint's execution path never calls it. ### 1.2 The actual bug lives in `prepare_global_scope()` `custom_component()` calls `build_custom_component_template()`, which flows into `create_class()` in `lfx/custom/validate.py`. That function calls `prepare_global_scope()`, and the submitted code is `exec()`'d shortly after. def prepare_global_scope(module):  exec_globals = globals().copy()  …  for node in module.body:  if isinstance(node, ast.Import | ast.ImportFrom):  imports.append(node)  elif isinstance(node, ast.ClassDef | ast.FunctionDef | ast.Assign | ast.AnnAssign):  definitions.append(node)  …  if definitions:  compiled_code = compile(combined_module, "<string>", "exec")  exec(compiled_code, exec_globals) # ← exec() happens here This function walks the submitted code's AST and only collects `import` statements and `class`/`def`/assignment nodes into `definitions`. That's the trap. * A top-level statement like `os.system(…)` is, at the AST level, an `ast.Expr` node. * `ast.Expr` isn't in the `isinstance` allow-list above → it's **silently dropped**. * Code placed **inside a class body** , however, is part of that `ClassDef` node - so when the class is defined (i.e., when `exec()` runs), that code executes right along with it. # ❌ Module level - classified as ast.Expr, silently dropped by prepare_global_scope() import os os.system("id > /tmp/pwned.txt") class PocComponent(Component):  … # ✅ Inside the class body - part of ClassDef, runs when exec() defines the class class PocComponent(Component):  os.system("id > /tmp/pwned.txt") # ← executes at class-definition time  … So the entire trick an attacker needs is: **put the payload inside the class body, not at module level.** No encoding tricks, no filter bypass gymnastics - just a simple, and simply devastating, design flaw. ## Exploit Chain The diagram below traces the full path from request to command execution. In short: Authenticated user (any privilege level)  │  ▼ POST /api/v1/custom_component { "code": "<malicious Python class>" }  │  ▼ build_custom_component_template() → create_class()  │  ▼ prepare_global_scope() - only ClassDef nodes get collected into definitions/exec target  │  ▼ compile_class_code() → exec(compiled_class, exec_globals)  │  ▼ Class body executes at definition time → RCE achieved No LLM involvement, no scanner to evade. One HTTP request is enough. ## Why the Scanner Didn't Catch This Langflow ships a separate AST-based scanner, `scan_code_security()`, in `langflow/agentic/helpers/code_security.py`. But it's wired only into the **Agentic Assistant path** (validating LLM-generated component code) - it's never called from `/api/v1/custom_component` at all. So CVE-2026–17633 isn't really a scanner bypass; it's exploiting a code path the scanner was never attached to in the first place. The scanner's own detection logic has a separate weakness (missing `vars()` coverage leading to a false `is_safe: True` verdict, tracked as CVE-2026–17632), which surfaced from analyzing the same codebase but is a distinct issue. ## Patch and Mitigation * Upgrade to Langflow 1.10.4+, which adds content validation to the `custom_component` endpoint * Keep `LANGFLOW_ALLOW_CUSTOM_COMPONENTS` set to `false` in production unless the feature is genuinely needed * If custom components must be enabled, restrict which accounts can reach that feature * Audit the group permissions of the container's runtime user (`gid=0` membership) to reduce lateral-movement / container-escape surface
dev.to
September 21, 2026 at 11:43 PM
The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents.
CISA orders urgent action on actively exploited Langflow RCE flaw
The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents.
www.bleepingcomputer.com
July 22, 2026 at 11:43 AM
Building #GenAI flows with Langflow is great, but what about when you want to use them in your own application?

Here's a quick video on how to use the Langflow API in @nodejs.org:

www.youtube.com/watch?v=DwvZ...
How to Use the Langflow API in Node.js
YouTube video by DataStax Developers
www.youtube.com
January 28, 2025 at 11:22 AM
4. Langflow — Visually build AI applications and agents

Langflow turns complicated AI architecture into connected visual blocks.

You can drag components onto a canvas and connect models, prompts, data sources, vector databases, tools, agents, APIs, and MCP servers.
September 25, 2026 at 12:00 PM
🚀 Skyrocketing! 🚀 (200+ new stars)

📦 langflow-ai / langflow
⭐ 16,282 (+208)
🗒 JavaScript

⛓️ Langflow is a dynamic graph where each node is an executable unit. Its modular and interactive design fosters rapid experimentation and prototyping, pushing hard on the limits of creativity.
GitHub - langflow-ai/langflow: ⛓️ Langflow is a dynamic graph where each node is an executable unit. Its modular and interactive design fosters rapid experimentation and prototyping, pushing hard on the limits of creativity.
⛓️ Langflow is a dynamic graph where each node is an executable unit. Its modular and interactive design fosters rapid experimentation and prototyping, pushing hard on the limits of creativity. - l...
github.com
April 9, 2024 at 4:51 AM
𝗦𝗲𝗮𝗺𝗹𝗲𝘀𝘀𝗹𝘆 𝗦𝘄𝗶𝘁𝗰𝗵 𝘁𝗼 𝗔𝗻𝘁𝗵𝗿𝗼𝗽𝗶𝗰 𝗶𝗻 𝗟𝗮𝗻𝗴𝗳𝗹𝗼𝘄!

Discover a straightforward method to switch AI models in Langflow, moving from OpenAI to Anthropic.

#Langflow #Anthropic #OpenAI #AI
July 6, 2025 at 1:09 PM