SSRF Vulnerability in Langflow API Request Component
CVE-2025-68477
7.7HIGH
What is CVE-2025-68477?
Langflow, an AI-powered agent and workflow tool, features an API Request component that allows for arbitrary HTTP requests to a user-defined URL without sufficient validation. This means that users can potentially issue requests to private IP addresses and cloud metadata endpoints, opening a door for Server-Side Request Forgery (SSRF) attacks. Attackers could exploit this flaw, especially as the flow execution endpoints can be accessed via just an API key. By controlling the API Request URL, malicious users could gain unauthorized access to internal resources and sensitive information, facilitating further attacks. Version 1.7.0 has addressed this vulnerability with key security enhancements.
Affected Version(s)
langflow < 1.7.0
