CVE-2025-57760

Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can invoke the internal CLI command langflow superuser to create a new administrative user. This results in full superuser access, even if the user initially registered through the UI as a regular (non-admin) account. A patched version has not been made public at this time.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
GitHub_MCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
VendorProductVersion
langflowlangflow
𝑥
< 1.5.0
langflowlangflow
1.5.0:dev0
langflowlangflow
1.5.0:dev1
langflowlangflow
1.5.0:dev10
langflowlangflow
1.5.0:dev11
langflowlangflow
1.5.0:dev12
langflowlangflow
1.5.0:dev13
langflowlangflow
1.5.0:dev14
langflowlangflow
1.5.0:dev15
langflowlangflow
1.5.0:dev16
langflowlangflow
1.5.0:dev17
langflowlangflow
1.5.0:dev18
langflowlangflow
1.5.0:dev19
langflowlangflow
1.5.0:dev2
langflowlangflow
1.5.0:dev20
langflowlangflow
1.5.0:dev21
langflowlangflow
1.5.0:dev22
langflowlangflow
1.5.0:dev23
langflowlangflow
1.5.0:dev24
langflowlangflow
1.5.0:dev25
langflowlangflow
1.5.0:dev26
langflowlangflow
1.5.0:dev27
langflowlangflow
1.5.0:dev28
langflowlangflow
1.5.0:dev29
langflowlangflow
1.5.0:dev3
langflowlangflow
1.5.0:dev30
langflowlangflow
1.5.0:dev31
langflowlangflow
1.5.0:dev4
langflowlangflow
1.5.0:dev5
langflowlangflow
1.5.0:dev6
langflowlangflow
1.5.0:dev7
langflowlangflow
1.5.0:dev8
langflowlangflow
1.5.0:dev9
𝑥
= Vulnerable software versions