Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 4 min
Buscando: "Langflow" — 83 resultados ✕ Limpiar búsqueda
22,082
Total alertas
4667
Críticas
16827
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81940] IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81941] IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute …
IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local stdio subprocess transport. This bypasses both the LANGFLOW_CUSTOM_COMPONENT_ADMIN_ONLY and LANGFLOW_BLOCK_CODE_INTERPRETER…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81213] IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information …
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81265] IBM Langflow OSS 1.0.0 through 1.11.5.
IBM Langflow OSS 1.0.0 through 1.11.5.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81268] IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows a…
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81211] IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-78575] IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-79742] IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-76059] IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code coul…
IBM Langflow OSS 1.0.0 through 1.11.5 An attacker who could submit custom component source code could bypass the static security scanner by crafting an annotated class-body assignment that resolved to a dangerous callable through alias tracking; the resolved value was never checked against the dangerous callable blocklist due to the logic error. If the crafted component reached the runtime executi…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-78569] IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary cod…
IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to execute arbitrary code due to an incomplete denylist in the security scanner.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-78571] IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19303] IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrar…
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19304] IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitiv…
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information from internal services due to a URL parser discrepancy.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19305] IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information …
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to server-side request forgery.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19306] IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from …
IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secret_key, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload directories) — by supplying absolute paths or traversal sequences in the files parameter of an authenticated build request. The file content…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19300] IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information …
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-19298] IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18899] IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to p…
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18904] IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information …
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-18729] IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitra…
IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.