File System Vulnerability in Langflow by Langflow AI
CVE-2026-55447

9.6CRITICAL

Key Information:

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-55447?

Langflow, a platform designed for building and deploying AI-driven agents, exhibits a serious vulnerability that allows attackers to read confidential files from the host file system. This issue arises from how files are processed within the Retrieval-Augmented Generation (RAG) framework. Attackers can exploit this flaw by controlling the files ingested into the system, leading to unauthorized access to any file specified by an absolute path. Notably, components reliant on BaseFileComponent, such as Docling and various file processing modules, are at risk. Users are encouraged to update to version 1.9.2 to mitigate this vulnerability.

Affected Version(s)

langflow < 1.9.2

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.