Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
Vulnerability Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code) contains a potential arbitrary file-read vulnerability, depending on the exact flow configuration used. By making a flow public, public execution of the flow is allowed. The execution request can contain a list of files that gets read by Langflow and fed into the LLM. The files path can be any path supported by the storage - it can be either a local file or S3 path if supported by the local configuration This vulnerability is fixed in 1.10.0.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
Vulnerability Type
文件名或路径的外部可控制
Vulnerability Title
Langflow 输入验证错误漏洞
Vulnerability Description
Langflow是Langflow团队开源的一个用于构建多代理和 RAG 应用程序的可视化框架。 Langflow 1.10.0之前版本存在输入验证错误漏洞,该漏洞源于可共享游乐场包含潜在任意文件读取问题,可能导致攻击者通过公开执行流程读取任意文件。
CVSS Information
N/A
Vulnerability Type
N/A