Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can invoke the internal CLI command langflow superuser to create a new administrative user. This results in full superuser access, even if the user initially registered through the UI as a regular (non-admin) account. A patched version has not been made public at this time.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Aug 2025 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Langflow
Langflow langflow |
|
Vendors & Products |
Langflow
Langflow langflow |
Mon, 25 Aug 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exists in Langflow containers where an authenticated user with RCE access can invoke the internal CLI command langflow superuser to create a new administrative user. This results in full superuser access, even if the user initially registered through the UI as a regular (non-admin) account. A patched version has not been made public at this time. | |
Title | Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation | |
Weaknesses | CWE-269 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-25T16:22:17.772Z
Updated: 2025-08-25T20:34:14.809Z
Reserved: 2025-08-19T15:16:22.917Z
Link: CVE-2025-57760

Updated: 2025-08-25T20:34:09.473Z

Status : Awaiting Analysis
Published: 2025-08-25T17:15:30.140
Modified: 2025-08-25T20:24:45.327
Link: CVE-2025-57760

No data.