← Back

CVE-2025-57760

nvd nist
Published: Aug 25, 2025Modified: Sep 3, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: security-advisories@github.com (Secondary)

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can invoke the internal CLI command langflow superuser to create a new administrative user. This results in full superuser access, even if the user initially registered through the UI as a regular (non-admin) account. A patched version has not been made public at this time.

Affected (33)

Products: Langflow: Langflow
1 product
Langflow
Configuration A
33 vulnerable
Vulnerable SoftwareAffected Versions
Langflow
Before 1.5.0
Version 1.5.0 dev0
Version 1.5.0 dev10
Version 1.5.0 dev11
Version 1.5.0 dev12
Version 1.5.0 dev13
Version 1.5.0 dev14
Version 1.5.0 dev15
Version 1.5.0 dev16
Version 1.5.0 dev17
Version 1.5.0 dev18
Version 1.5.0 dev19
Version 1.5.0 dev1
Version 1.5.0 dev20
Version 1.5.0 dev21
Version 1.5.0 dev22
Version 1.5.0 dev23
Version 1.5.0 dev24
Version 1.5.0 dev25
Version 1.5.0 dev26
Version 1.5.0 dev27
Version 1.5.0 dev28
Version 1.5.0 dev29
Version 1.5.0 dev2
Version 1.5.0 dev30
Version 1.5.0 dev31
Version 1.5.0 dev3
Version 1.5.0 dev4
Version 1.5.0 dev5
Version 1.5.0 dev6
Version 1.5.0 dev7
Version 1.5.0 dev8
Version 1.5.0 dev9

References (3)

Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
Third Party Advisory

Timeline

No history available yet.