Critical severity9.6GHSA Advisory· Published Jun 23, 2026· Updated Jun 24, 2026
CVE-2026-55447
CVE-2026-55447
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All components based on BaseFileComponent are vulnerable to the vulnerability. This includes Docling (DoclingInlineComponent), Docling Serve, DoclingRemoteComponent), Read File (FileComponent), NVIDIA Retriever Extraction (NvidiaIngestComponent), Video File (VideoFileComponent), and Unstructured API (UnstructuredComponent). This vulnerability is fixed in 1.9.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
langflowPyPI | < 1.9.2 | 1.9.2 |
Affected products
2cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*range: <1.9.2
- (no CPE)range: < 1.9.2
Patches
Vulnerability mechanics
References
3- github.com/langflow-ai/langflow/pull/12945nvdIssue TrackingPatchWEB
- github.com/langflow-ai/langflow/security/advisories/GHSA-ccv6-r384-xp75nvdExploitPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-ccv6-r384-xp75ghsaADVISORY
News mentions
1- Langflow: Four CVEs Disclosed Together — Two Critical, Including File-Read and IDOR BugsVypr Intelligence · Jun 19, 2026