CVE-2026-55447
CRITICALLangflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
Title source: cnaDescription
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All components based on BaseFileComponent are vulnerable to the vulnerability. This includes Docling (DoclingInlineComponent), Docling Serve, DoclingRemoteComponent), Read File (FileComponent), NVIDIA Retriever Extraction (NvidiaIngestComponent), Video File (VideoFileComponent), and Unstructured API (UnstructuredComponent). This vulnerability is fixed in 1.9.2.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/langflow-ai/langflow/security/advisories/GHSA-ccv6-r384-xp75
X_Refsource_Misc x_refsource_misc
https://github.com/langflow-ai/langflow/pull/12945
Scores
CVSS v3
9.6
EPSS
0.0047
EPSS Percentile
38.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-200
CWE-61
Status
published
Products (2)
langflow/langflow
< 1.9.2
langflow-ai/langflow
< 1.9.2
Published
Jun 23, 2026
Tracked Since
Jun 23, 2026