vulnerabilities
'We can't build a secure sandbox nor monitor our own model tests properly' is not a flex - and Hugging Face's Thomas Wolf has views
"Issues that depend on compromised or malicious inputs already present in that context generally fall outside our bug bounty scope."
watchTowr also credited after letting “our small pets walk across our keyboard, and watching what happens.”
Langflow
|
Jun 15, 2026
"“These deployments rarely got the hardening a production web app would. They run with default authentication settings and sit on public IPs because someone needed to demo a flow to a stakeholder..."