Jordan Frazier 7b84a7e426 feat: add SSRF protection configuration for API Requests (#10544)
* Add SSRF protection configuration for API Requests

* clean up, add env vars to settings

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes (attempt 3/3)

* move ip blocklist to lazy load, simplify functions

* [autofix.ci] apply automated fixes

* refactor: replace global variable with functools.cache for IP ranges

* refactor: simplify IP blocking logic with comprehension

* refactor: remove unused url parameter from validation helpers

* refactor: restructure exception handling in IP validation

* refactor: use parenthesized context managers in SSRF tests

* refactor: apply parenthesized context manager syntax in tests

* Update docs to reflect behavior when params are mixed

* docs update

* whitespace

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

* [autofix.ci] apply automated fixes

* starter projects

* [autofix.ci] apply automated fixes

* [autofix.ci] apply automated fixes (attempt 2/3)

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Gabriel Luiz Freitas Almeida <gabriel@langflow.org>
2025-11-12 02:54:14 +00:00
2025-11-11 21:51:28 +00:00

Langflow logo

Release Notes PyPI - License PyPI - Downloads GitHub star chart Open Issues Twitter YouTube Channel Discord Server Ask DeepWiki

Caution

  • Langflow versions 1.6.0 through 1.6.3 have a critical bug where .env files are not read, potentially causing security vulnerabilities. DO NOT upgrade to these versions if you use .env files for configuration. Instead, upgrade to 1.6.4, which includes a fix for this bug.
  • Windows users of Langflow Desktop should not use the in-app update feature to upgrade to Langflow version 1.6.0. For upgrade instructions, see Windows Desktop update issue.
  • Users must update to Langflow >= 1.3 to protect against CVE-2025-3248
  • Users must update to Langflow >= 1.5.1 to protect against CVE-2025-57760

For security information, see our Security Policy and Security Advisories.

Langflow is a powerful tool for building and deploying AI-powered agents and workflows. It provides developers with both a visual authoring experience and built-in API and MCP servers that turn every workflow into a tool that can be integrated into applications built on any framework or stack. Langflow comes with batteries included and supports all major LLMs, vector databases and a growing library of AI tools.

Highlight features

  • Visual builder interface to quickly get started and iterate.
  • Source code access lets you customize any component using Python.
  • Interactive playground to immediately test and refine your flows with step-by-step control.
  • Multi-agent orchestration with conversation management and retrieval.
  • Deploy as an API or export as JSON for Python apps.
  • Deploy as an MCP server and turn your flows into tools for MCP clients.
  • Observability with LangSmith, LangFuse and other integrations.
  • Enterprise-ready security and scalability.

Quickstart

Requires Python 3.103.13 and uv (recommended package manager).

Install

uv pip install langflow -U

Installs the latest Langflow package.

Run

uv run langflow run

Starts the Langflow server at http://127.0.0.1:7860.

That's it! You're ready to build with Langflow 🎉

Other install options

Install from repo

If you're contributing or running from source, see DEVELOPMENT.md for setup instructions.

📦 Deployment

Langflow is completely open source, and you can deploy it to all major clouds. To learn how to use Docker to deploy Langflow, see the Docker deployment guide.

Stay up-to-date

Star Langflow on GitHub to be instantly notified of new releases.

Star Langflow

👋 Contribute

We welcome contributions from developers of all levels. If you'd like to contribute, please check our contributing guidelines and help make Langflow more accessible.


Star History Chart

❤️ Contributors

langflow contributors

Description
Langflow is a powerful tool for building and deploying AI-powered agents and workflows.
Readme MIT 2.3 GiB
Languages
Python 64.5%
TypeScript 23.4%
JavaScript 11.4%
CSS 0.3%
Makefile 0.2%
Other 0.1%