Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints (CVE-2026-12940) | HOL Guard CVE