0.8.4
2 years ago
2 days ago
Known vulnerabilities in the langflow-base package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? There is no fixed version for | [0,) |
Affected versions of this package are vulnerable to Missing Authorization via the How to fix Missing Authorization? There is no fixed version for | [0,) |
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? There is no fixed version for | [0,) |
Affected versions of this package are vulnerable to Missing Authorization via the How to fix Missing Authorization? There is no fixed version for | [0.0.83,) |
Affected versions of this package are vulnerable to Arbitrary Code Injection through the Agentic Assistant validation process. An attacker can execute arbitrary server-side Python code by supplying input that causes the assistant to return malicious component code, which is then instantiated during validation. How to fix Arbitrary Code Injection? A fix was pushed into the | [0,) |
Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? A fix was pushed into the | [0,) |
Affected versions of this package are vulnerable to Missing Authorization via the How to fix Missing Authorization? A fix was pushed into the | [0,) |
Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the disk cache service. An attacker can execute arbitrary code by supplying crafted data that is deserialized without proper validation. How to fix Deserialization of Untrusted Data? There is no fixed version for | [0,) |
Affected versions of this package are vulnerable to Origin Validation Error via an overly permissive CORS configuration in the Note: The option was added in version 0.6.0 (used in langflow 1.6.x) to restrict allowed origins with How to fix Origin Validation Error? There is no fixed version for | [0,) |