SSRF Vulnerability in Langflow API Request Component
CVE-2025-68477

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
19 December 2025

What is CVE-2025-68477?

Langflow, an AI-powered agent and workflow tool, features an API Request component that allows for arbitrary HTTP requests to a user-defined URL without sufficient validation. This means that users can potentially issue requests to private IP addresses and cloud metadata endpoints, opening a door for Server-Side Request Forgery (SSRF) attacks. Attackers could exploit this flaw, especially as the flow execution endpoints can be accessed via just an API key. By controlling the API Request URL, malicious users could gain unauthorized access to internal resources and sensitive information, facilitating further attacks. Version 1.7.0 has addressed this vulnerability with key security enhancements.

Affected Version(s)

langflow < 1.7.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-68477 : SSRF Vulnerability in Langflow API Request Component