Unauthenticated Data Upload Vulnerability in Langflow by Langflow AI
CVE-2026-55450

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-55450?

An unauthenticated data upload vulnerability exists in Langflow, a tool for building AI-powered agents and workflows. Prior to version 1.9.1, this vulnerability enables malicious users to upload arbitrary data to the server without restrictions, potentially leading to server space exhaustion. Additionally, the server responses include the absolute path of uploaded files, risking information leakage that can be exploited for further attacks. This issue has been addressed in version 1.9.1.

Affected Version(s)

langflow < 1.9.1

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.