Langflow是Langflow团队开源的一个用于构建多代理和 RAG 应用程序的可视化框架。 Langflow 1.9.0之前版本存在路径遍历漏洞,该漏洞源于用户提供的知识库名称直接用于创建文件路径,未经正确清理或包含检查,可能导致经过身份验证的攻击者在服务器文件系统上任意目录创建文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| langflow-ai | langflow | < 1.9.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| langflow-ai | langflow | < 1.9.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48519 | 9.6 CRITICAL | Langflow: Unauthenticated RCE in Shareable Playgrounds |
| CVE-2026-55447 | 9.6 CRITICAL | Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit |
| CVE-2026-55450 | 9.3 CRITICAL | Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak |
| CVE-2026-33760 | 8.8 HIGH | Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints |
| CVE-2026-55255 | 8.4 HIGH | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attacker |
| CVE-2026-55446 | 7.5 HIGH | Langflow: Unauthenticated DoS through multipart form boundary file upload |
| CVE-2026-48520 | 6.1 MEDIUM | Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read |
| CVE-2026-55423 | 6.1 MEDIUM | Langflow: Logout button does not clear session |
No comments yet