https://github.com/langflow-ai/langflow
· scanned 2026-06-05 04:43 UTC (4 hours, 19 minutes ago)
· 10 languages
2202 findings (78 legacy + 2124 scanner) 11/13 scanners ran 80th percentile · Javascript · small (2-20K LoC) Scanner says 61 (higher by 21)
Last scanned 4 hours, 19 minutes ago · v2 · 1140 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
70.0 | 0.20 | 14.00 |
documentation_score |
60.0 | 0.15 | 9.00 |
practices_score |
87.0 | 0.15 | 13.05 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 81.8 |
Showing 863 of 1140 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/ci.yml:325
dependencylegacy
.github/workflows/ci.yml:269
dependencylegacy
.github/workflows/ci.yml:72
dependencylegacy
.github/workflows/ci.yml:450
dependencylegacy
.github/workflows/ci.yml:302
dependencylegacy
.github/workflows/ci.yml:270
dependencylegacy
.github/workflows/ci.yml:377
dependencylegacy
.github/workflows/ci.yml:376
dependencylegacy
.github/workflows/deploy-docs-draft.yml:178
dependencylegacy
.github/workflows/deploy-docs-draft.yml:179
dependencylegacy
.github/workflows/ci.yml:323
dependencylegacy
.github/workflows/ci.yml:268
dependencylegacy
.github/workflows/ci.yml:71
dependencylegacy
.github/workflows/ci.yml:324
dependencylegacy
.github/workflows/ci.yml:73
dependencylegacy
.github/workflows/ci.yml:326
dependencylegacy
.github/workflows/ci.yml:74
dependencylegacy
.github/workflows/mend.yml:50
dependencylegacy
.github/workflows/mend.yml:53
dependencylegacy
.github/workflows/mend.yml:54
dependencylegacy
.github/workflows/mend.yml:52
dependencylegacy
.github/workflows/mend.yml:51
dependencylegacy
src/lfx/src/lfx/components/mongodb/mongodb_atlas.py:31
owaspprivate_key_in_repo
docs/docusaurus.config.js:537
secrets
src/frontend/src/components/core/parameterRenderComponent/components/queryComponent/index.tsx:18
secrets
src/frontend/src/components/core/parameterRenderComponent/components/textAreaComponent/index.tsx:21
secrets
src/lfx/src/lfx/schema/table.py:114
secrets
.github/workflows/lint-js.yml:38
dependencylegacy
.github/workflows/docker-build-v2.yml:453
dependencylegacy
.github/workflows/docker-build-v2.yml:382
dependencylegacy
.github/workflows/docker-build-v2.yml:307
dependencylegacy
.github/workflows/docker-build-v2.yml:236
dependencylegacy
.github/workflows/docker-build-v2.yml:165
dependencylegacy
.github/workflows/docker-build-v2.yml:112
dependencylegacy
.github/workflows/docker-build-v2.yml:66
dependencylegacy
.github/workflows/lint-js.yml:25
dependencylegacy
.github/workflows/style-check-py.yml:19
dependencylegacy
.github/workflows/codeql.yml:33
dependencylegacy
.github/workflows/create-release.yml:23
dependencylegacy
.github/workflows/lint-js.yml:32
dependencylegacy
.github/workflows/docker-build-v2.yml:117
dependencylegacy
.github/workflows/docker-build-v2.yml:71
dependencylegacy
.github/workflows/style-check-py.yml:21
dependencylegacy
.github/workflows/codeql.yml:64
dependencylegacy
.github/workflows/codeql.yml:51
dependencylegacy
.github/workflows/codeql.yml:37
dependencylegacy
.github/workflows/create-release.yml:28
dependencylegacy
.github/workflows/auto-update.yml:13
dependencylegacy
.github/workflows/db-migration-validation.yml:309
dependencylegacy
.github/workflows/migration-validation.yml:19
dependencylegacy
.github/workflows/db-migration-validation.yml:324
dependencylegacy
.github/workflows/db-migration-validation.yml:33
dependencylegacy
docs/src/components/CopyPageButton.tsx:88
xsslegacy
src/backend/base/langflow/services/store/service.py:480
integritysync-io-in-asyncperformance
src/backend/base/langflow/services/store/service.py:378
integritysync-io-in-asyncperformance
src/lfx/src/lfx/components/files_and_knowledge/save_file.py:755
integritysync-io-in-asyncperformance
src/lfx/src/lfx/components/files_and_knowledge/save_file.py:804
integritysync-io-in-asyncperformance
src/backend/base/langflow/api/v1/models.py:825
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v2/files.py:781
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v2/files.py:782
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/api_key.py:43
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/deployments.py:1431
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/files.py:286
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v2/files.py:712
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v2/files.py:435
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/flows.py:344
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/folders.py:72
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/knowledge_bases.py:644
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/knowledge_bases.py:665
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/knowledge_bases.py:666
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/flows.py:464
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/projects.py:439
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/deployments.py:388
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v2/mcp.py:365
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/variable.py:241
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/flow_version.py:295
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/users.py:84
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/users.py:115
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/deployments.py:1316
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/flows.py:211
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/folders.py:63
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/mcp_projects.py:482
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/projects.py:283
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/deployments.py:423
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v2/mcp.py:345
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/deployments.py:1021
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/variable.py:192
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/flow_version.py:227
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v2/mcp.py:324
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/users.py:21
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/agentic/api/router.py:276
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/agentic/api/router.py:252
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/chat.py:163
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/chat.py:640
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/chat.py:321
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/chat.py:777
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/chat.py:279
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/knowledge_bases.py:711
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/api_key.py:30
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/deployments.py:808
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/deployments.py:481
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/flow_events.py:62
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/flows.py:89
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/flows.py:368
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/folders.py:22
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/knowledge_bases.py:81
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/knowledge_bases.py:82
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/projects.py:61
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/deployments.py:313
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/openai_responses.py:590
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/flow_version.py:196
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/endpoints.py:1010
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/variable.py:102
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/endpoints.py:1101
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/endpoints.py:1060
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/variable.py:306
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v2/files.py:532
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/flows.py:503
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/agentic/api/router.py:133
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v2/workflow.py:101
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/mcp.py:146
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/mcp_projects.py:404
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/knowledge_bases.py:282
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/mcp_projects.py:693
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/knowledge_bases.py:173
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/endpoints.py:976
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/endpoints.py:981
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/login.py:145
authowaspauth.fastapi.unauth_mutation
src/lfx/src/lfx/cli/serve_app.py:415
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/api_key.py:56
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/models.py:750
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v2/workflow.py:645
authowaspauth.fastapi.unauth_mutation
src/lfx/src/lfx/cli/serve_app.py:484
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/models.py:605
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/folders.py:92
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/files.py:76
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/flows.py:406
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/projects.py:508
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v2/files.py:130
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v2/files.py:131
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/models.py:321
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v2/files.py:691
authowaspauth.fastapi.unauth_mutation
src/backend/base/langflow/api/v1/flows.py:263
authowaspauth.fastapi.unauth_mutation
.github/workflows/docker-build.yml:257
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build.yml:277
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build.yml:364
supply-chaingithub-actionspinned-dependencies
src/backend/base/langflow/agentic/flows/LangflowAssistant.json:890
owaspeval_used
src/backend/base/langflow/agentic/helpers/code_security.py:13
owaspeval_used
src/lfx/src/lfx/components/llm_operations/lambda_filter.py:242
owaspeval_used
src/lfx/src/lfx/custom/code_parser/code_parser.py:164
owaspeval_used
src/lfx/src/lfx/io/schema.py:272
owaspeval_used
src/backend/base/langflow/agentic/flows/LangflowAssistant.json:890
owaspexec_used
src/backend/base/langflow/agentic/helpers/code_security.py:12
owaspexec_used
src/lfx/src/lfx/components/tools/python_code_structured_tool.py:152
owaspexec_used
src/lfx/src/lfx/custom/code_parser/code_parser.py:144
owaspexec_used
src/lfx/src/lfx/custom/validate.py:67
owaspexec_used
docs/docs/API-Reference/python-examples/api-openai-responses/additional-configuration-for-openai-client-libraries.py:26
qualitylegacy
docs/docs/API-Reference/python-examples/api-openai-responses/additional-configuration-for-openai-client-libraries.py:20
qualitylegacy
.well-known/security.txt
qualitylegacy
docker_example/Dockerfile:1
supply-chaindockerpinned-dependencies
.github/workflows/create-release.yml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/codeql.yml:37
supply-chaingithub-actionspinned-dependencies
.github/workflows/codeql.yml:51
supply-chaingithub-actionspinned-dependencies
.github/workflows/codeql.yml:64
supply-chaingithub-actionspinned-dependencies
.github/workflows/style-check-py.yml:21
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:71
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:117
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:182
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:185
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:191
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:198
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:210
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:253
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:256
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:262
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:269
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:281
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:324
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:327
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build-v2.yml:333
supply-chaingithub-actionspinned-dependencies
.github/workflows/nightly_build.yml:98
supply-chaingithub-actionspinned-dependencies
.github/workflows/release_bundles.yml:41
supply-chaingithub-actionspinned-dependencies
.github/workflows/release_bundles.yml:121
supply-chaingithub-actionspinned-dependencies
.github/workflows/release_bundles.yml:191
supply-chaingithub-actionspinned-dependencies
.github/workflows/release_nightly.yml:70
supply-chaingithub-actionspinned-dependencies
.github/workflows/release_nightly.yml:163
supply-chaingithub-actionspinned-dependencies
.github/workflows/release_nightly.yml:263
supply-chaingithub-actionspinned-dependencies
.github/workflows/release_nightly.yml:410
supply-chaingithub-actionspinned-dependencies
.github/workflows/release_nightly.yml:438
supply-chaingithub-actionspinned-dependencies
.github/workflows/deploy_gh-pages.yml:36
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:228
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:358
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:451
supply-chaingithub-actionspinned-dependencies
.github/workflows/db-migration-validation.yml:53
supply-chaingithub-actionspinned-dependencies
.github/workflows/conventional-labels.yml:16
supply-chaingithub-actionspinned-dependencies
.github/workflows/gp-download.yml:79
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:194
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:247
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:296
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:346
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:416
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:485
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:595
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:64
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:100
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:103
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:109
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:116
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:129
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:160
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:195
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:198
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:204
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:211
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:224
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:255
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:290
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:293
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:299
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-nightly-build.yml:306
supply-chaingithub-actionspinned-dependencies
.github/workflows/lint-py.yml:34
supply-chaingithub-actionspinned-dependencies
.github/workflows/py_autofix.yml:21
supply-chaingithub-actionspinned-dependencies
.github/workflows/py_autofix.yml:39
supply-chaingithub-actionspinned-dependencies
.github/workflows/py_autofix.yml:90
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-lfx.yml:51
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-lfx.yml:101
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-lfx.yml:132
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-lfx.yml:215
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-lfx.yml:232
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-lfx.yml:235
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-lfx.yml:241
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-lfx.yml:249
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-lfx.yml:264
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-lfx.yml:337
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build.yml:213
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build.yml:242
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build.yml:251
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build.yml:270
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build.yml:337
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build.yml:347
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build.yml:354
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-build.yml:392
supply-chaingithub-actionspinned-dependencies
.github/workflows/deploy-docs-draft.yml:150
supply-chaingithub-actionspinned-dependencies
.github/workflows/deploy-docs-draft.yml:158
supply-chaingithub-actionspinned-dependencies
.github/workflows/deploy-docs-draft.yml:169
supply-chaingithub-actionspinned-dependencies
.github/workflows/deploy-docs-draft.yml:258
supply-chaingithub-actionspinned-dependencies
.github/workflows/migration-validation.yml:39
supply-chaingithub-actionspinned-dependencies
.github/workflows/lint-js.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/nightly_build.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/deploy-storybook.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/gp-download.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release-lfx.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/docker-build.yml
supply-chaingithub-actionsleast-privilege
Showing first 300 of 863. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/21f5a3bf-888a-438b-82df-af3a9dc3f48f/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/21f5a3bf-888a-438b-82df-af3a9dc3f48f/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.