Skip to content

Conversation

@augustocesarperin
Copy link

@augustocesarperin augustocesarperin commented Jan 17, 2026

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • Description
  • Source code location
  • Summary

Comments
Adding pip ecosystem and package mapping for langflow. Affected versions <= 1.6.9, patched in 1.7.1.
Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-34291

@github-actions github-actions bot changed the base branch from main to augustocesarperin/advisory-improvement-6665 January 17, 2026 16:11
@augustocesarperin augustocesarperin changed the title [GHSA-577h-p2hh-v4mv] Langflow versions up to and including 1.6.9 contain a... [GHSA-577h-p2hh-v4mv] Langflow CORS Account Takeover and RCE Jan 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants