Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the POST /api/v1/custom_component endpoint and provide a Python script.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Langflow |
Langflow |
* |
0.6.19 (including) |
References