Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the POST /api/v1/custom_component endpoint and provide a Python script.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Langflow | Langflow | * | 0.6.19 (including) |
References