Remote Code Execution Vulnerability in Langflow by Langflow AI
CVE-2026-48519
9.6CRITICAL
Key Information:
- Vendor
Langflow-ai
- Status
- Vendor
- CVE Published:
- 23 June 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-48519?
Langflow, an innovative platform for building AI-powered agents, experienced a critical vulnerability prior to version 1.9.2 that allowed for remote code execution via its 'Shareable Playground' feature. This flaw enabled unauthorized users to execute arbitrary Python code by exploiting a public flow ID without authentication. The vulnerable API endpoint, /api/v1/build_public_tmp, facilitated the injection of malicious code through a JSON payload. Users are strongly advised to upgrade to version 1.9.2 or later to mitigate this risk.
Affected Version(s)
langflow < 1.9.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
