PT-2026-46232 · Langflow · Langflow
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Langflow versions prior to 1.9.2
Description
The Shareable Playground (also known as Public Flows) feature allows unauthenticated users to execute workflows via a link. A flaw in the '/api/v1/build public tmp' endpoint enables attackers to execute arbitrary Python code on the server by submitting a crafted JSON payload. The issue occurs because the system allows providing custom Python code within the
data.nodes[X].data.node.template.code.value variable during flow execution. Over 30,900 potentially affected deployments were identified via FOFA. This can lead to full system compromise, data theft, or service disruption.Recommendations
Update to version 1.9.2.
As a temporary workaround, disable the Shareable Playground feature to prevent unauthenticated access to the vulnerable endpoint.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langflow