FlowHound¶

FlowHound is an automated AI/ML infrastructure exploitation framework for scanning and testing insecure Langflow and MLflow deployments.
Authorised use only
FlowHound is intended exclusively for authorised security testing. Do not run it against systems you do not own or have explicit written permission to test.
What is FlowHound?¶
Langflow and MLflow are widely deployed AI/ML platforms. When deployed without proper hardening they expose unauthenticated and authenticated attack surfaces. FlowHound automates the entire assessment workflow:
- Version detection — probes the target to identify the running application and its version. When
--applicationis provided the corresponding detector is called directly; otherwise all registered detectors are tried in sequence. - CVE lookup — searches the bundled vulnerability database for CVE records matching the detected application, version range, and authentication state.
- Exploit dispatch — dynamically loads each matching exploit module and executes it.
- Payload injection — optionally replaces the built-in
idprobe with a custom shell command or a reverse TCP shell.
Who is it for?¶
- Penetration testers assessing Langflow- or MLflow-backed AI/ML infrastructure.
- Security engineers validating patch compliance on internal deployments.
- Red teams evaluating exposure of AI/ML platform instances in lab environments.
Major capabilities¶
| Capability | Description |
|---|---|
| Multi-target detection | Auto-detects Langflow or MLflow from the live API; override with --application |
| CVE database | Bundled JSON database of known CVEs with CVSS scores, version ranges, and module types (exploit/auxiliary) |
| Unauthenticated exploits | Exploits that require no credentials |
| Authenticated exploits | Exploits that leverage supplied credentials |
| Auxiliary scans | scan command for executing non-RCE modules (file read, SSRF) |
| Custom payloads | --command for arbitrary shell commands; --reverse_shell for a reverse TCP shell |
| Autopwn mode | --autopwn runs all matching exploits rather than stopping at the first success |
| CVE targeting | --cve limits execution to a single named CVE |
| Proxy support | Route all traffic through an HTTP(S) proxy |
sniff mode |
Detect version and list applicable modules without launching any exploits |
Quick start¶
# Install
pip install flowhound
# Detect version and list modules — no exploits or scans launched
flowhound sniff --url http://TARGET:7860
# Unauthenticated attack (Langflow — auto-detected)
flowhound attack --url http://TARGET:7860
# Target a single exploit CVE
flowhound attack --url http://TARGET:7860 --cve CVE-2026-9198
# Authenticated attack
flowhound attack --url http://TARGET:7860 --username admin --password secret
# Auxiliary scan (e.g. MLflow arbitrary file read)
flowhound scan --url http://TARGET:5000 --cve CVE-2023-1177 --f_path /etc/passwd
Documentation¶
| Page | Contents |
|---|---|
| Installation | Full installation instructions and requirements |
| Quick Start | First run walkthrough |
| CLI Overview | Complete CLI reference |
| Attack | attack command in depth |
| Scan | scan command in depth |
| Sniff | sniff command in depth |
| Vulnerability Database | CVE database schema and CVE coverage |
| Architecture | Module architecture and exploit pipeline |
| Development Setup | Developer environment and tooling |
| Contributing | How to contribute |