CVE-2024-7297

8.8HIGH

Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request

发布于: 7/30/2024更新于: 6/24/2025

描述

Langflow versions prior to 1.0.13 suffer from a Privilege Escalation vulnerability, allowing a remote and low privileged attacker to gain super admin privileges by performing a mass assignment request on the '/api/v1/users' endpoint.

AI分析AI驱动

受影响产品

langflowlangflow

参考资料