← Back to browse · API

CVE-2024-37014

Severity
HIGH
CVSS
8.8
EPSS
0.57485
Risk score
55.32
CISA KEV
No
PoC
No
Published
2024-06-10
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-0213, GHSA-QG33-X2C5-6P44, PYSEC-2024-177
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-0213

Description

Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.

References