Medium severity6.1GHSA Advisory· Published Jun 23, 2026· Updated Jun 26, 2026
CVE-2026-48520
CVE-2026-48520
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code) contains a potential arbitrary file-read vulnerability, depending on the exact flow configuration used. By making a flow public, public execution of the flow is allowed. The execution request can contain a list of files that gets read by Langflow and fed into the LLM. The files path can be any path supported by the storage - it can be either a local file or S3 path if supported by the local configuration This vulnerability is fixed in 1.10.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
langflowPyPI | < 1.10.0 | 1.10.0 |
Affected products
2cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*range: <1.10.0
- (no CPE)range: < 1.10.0
Patches
Vulnerability mechanics
References
4- github.com/langflow-ai/langflow/security/advisories/GHSA-rcjh-r59h-gq37nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-rcjh-r59h-gq37ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-48520ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/langflow/PYSEC-2026-244.yamlghsaWEB
News mentions
2- ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreThe Hacker News · Jul 6, 2026
- Langflow Flaws Exposed AI Servers to TakeoverGovInfoSecurity · Jul 1, 2026