← Back to browse · API

CVE-2026-55450

Severity
CRITICAL
CVSS
9.3
EPSS
0.11819
Risk score
41.34
CISA KEV
No
PoC
No
Published
2026-06-23
Modified
2026-06-23
First seen
2026-08-07
Aliases
EUVD-2026-38511, GHSA-X223-P2GF-V735, PYSEC-2026-224
Products
langflow-ai:langflow < 1.9.1
Sources
euvd EUVD-2026-38511

Description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow. This can lead to space exhaustion on the server. In addition, in the response, the absolute path of the uploaded file is reported to the attacker, which is an information leak that can assist in chaining other primitives. This vulnerability is fixed in 1.9.1.

References