← Back to browse · API

CVE-2024-7297

Severity
HIGH
CVSS
8.8
EPSS
0.21346
Risk score
42.67
CISA KEV
No
PoC
No
Published
2024-07-30
Modified
2026-03-27
First seen
2026-08-07
Aliases
EUVD-2024-48240, GHSA-6J6G-J4QM-M9JF
Products
-
Sources
euvd EUVD-2024-48240

Description

Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request on the '/api/v1/users' endpoint.

References