Langflow changelog: what's new each month
Every stable Langflow release summarised by month: the highlights, new features, improvements, fixes and anything you need to act on. 3 months covered; the current month updates daily.
October 2026 · so far
1 release: 1.12.5
October brought important security hardening and stability improvements to Langflow. The release focused on fixing critical issues in MCP (Model Context Protocol) handling and enforcing stricter access controls.
Highlights
- Security restrictions now limit built-in code execution to administrators only.
- MCP server credentials are redacted from management responses to prevent exposure.
- Chat attachments are now confined to authorized storage locations.
- MCP session leaks and timeout retry issues have been resolved.
Improved
- MCP server discovery now has bounded concurrency and proper cleanup to prevent resource exhaustion.
- Global variable headers from the environment are now correctly forwarded through MCP.
- A2A (agent-to-agent) execution now enforces authenticated execution policy.
- Vulnerable dependencies have been upgraded for improved security.
Fixed
- MCP session leak and timeout retry handling.
- MCP server discovery concurrency and cleanup issues.
- Stored chat attachments were not properly confined to authorized storage.
- Server credentials were being exposed in management responses.
September 2026
6 releases: 1.11.6 → 1.12.4
September brought role-based access control foundations, improved model provider handling, and numerous stability fixes across the platform. The release series solidified authorization contracts and addressed edge cases in component management and knowledge base operations.
Highlights
- Role-based access control (RBAC) authorization system completed with scoped visibility and admin policy enforcement.
- Pluggable model provider policy allows flexible control over which providers can be used.
- Assistant slash command menu and execution budget introduced for better workflow control.
- Telemetry can now export to any OTLP backend for flexible observability integration.
- Component registry and knowledge base operations made more robust with improved edge case handling.
New
- Pluggable model provider policy for customizable provider access control.
- Scoped authorization visibility prefilter for granular permission management.
- Assistant slash command menu with 100-step execution budget.
- Option to opt out of graph state in streamed responses via agui.
- Support for exporting application telemetry to any OTLP backend.
- Guardrails integration with optional combined rule and model checks.
- Watsonx model detection behind LiteLLM proxy.
Improved
- Component updates after 1.12 upgrade now preserve workflow edges.
- Knowledge base allows recreating names after locked deletion.
- Assistant remains reopenable mid-run without interruption.
- Database constraint naming made consistent across creation paths.
- Multiple knowledge base columns can now be vectorized together.
- MCP server errors properly reported during edit operations.
- Downloaded project filenames preserve GB18030 characters.
- OpenSearch now selects k-NN method by engine instead of hardcoding.
Fixed
- Custom component policy errors now surface in build failures instead of silently failing.
- Redundant model provider refreshes eliminated.
- CLI properly cleans up failed serve inputs.
- Built-in registry no longer wiped by lazy loading.
- Mixed blocked DNS answers with IP allowlists now rejected.
- Database credentials removed from settings errors and console output.
August 2026
4 releases: 1.11.2 → 1.11.5
August brought security hardening across multiple components and fixes for streaming, authentication, and file handling. The release series focused on closing protocol gaps and improving reliability in cloud and local deployments.
Highlights
- Security fixes for SQL injection, SSRF vulnerabilities, and symlink traversal attacks across file handling and model providers.
- Agentic experience now enabled by default, improving out-of-box user experience.
- Improved streaming content accumulation and chained input handling for better conversation flow.
- Enhanced AWS file fallbacks and retry logic for concurrent database operations.
- MCP (Model Context Protocol) stability improvements including SDK version pinning and stdio component policy hardening.
New
- Optional bypass for the multi-worker in-memory queue guard on the server.
- Improved tracing with orphan span detachment before database flushes.
Improved
- Streaming content properly increments previouscontent for continuous accumulation.
- Model selection now respects explicit clearing instead of auto-filling cross-provider defaults.
- AWS fallback handling in Write File component.
- Flow updates retry automatically on SQLite lock conflicts.
- Refresh sessions stay alive on HTTP connections.
- MCP search registry now matches displayname and description consistently.
- Keyboard shortcuts reset to defaults when modifier-only saved shortcuts are cleared.
- Memory client import deferred to startup for faster initialization.
Fixed
- Security: SQL connection target query overrides blocked.
- Security: FileInput paths contained within allowed boundaries.
- Security: Ambiguous URL authorities rejected.
- Security: Symlinks skipped in GitExtractor.
- Security: Model-provider SSRF follow-up gaps closed.
- Markdown sanitization schema protocol gaps fixed (CVE audit GHSA-7rw4-v4gc-r864).
Summaries are written automatically from the official release notes (full changelog ↗); check the original notes before relying on a detail. Langflow: pricing, features and alternatives · All changelogs
