Unauthenticated Data Upload Vulnerability in Langflow by Langflow AI
CVE-2026-55450
9.3CRITICAL
What is CVE-2026-55450?
An unauthenticated data upload vulnerability exists in Langflow, a tool for building AI-powered agents and workflows. Prior to version 1.9.1, this vulnerability enables malicious users to upload arbitrary data to the server without restrictions, potentially leading to server space exhaustion. Additionally, the server responses include the absolute path of uploaded files, risking information leakage that can be exploited for further attacks. This issue has been addressed in version 1.9.1.
Affected Version(s)
langflow < 1.9.1
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
