PT-2026-46232 · Langflow · Langflow

·

CVE-2026-48519

·

Published

2026-06-04

·

Updated

2026-07-17

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Langflow versions prior to 1.9.2
Description The Shareable Playground (also known as Public Flows) feature allows unauthenticated users to execute workflows via a link. A flaw in the '/api/v1/build public tmp' endpoint enables attackers to execute arbitrary Python code on the server by submitting a crafted JSON payload. The issue occurs because the system allows providing custom Python code within the data.nodes[X].data.node.template.code.value variable during flow execution. Over 30,900 potentially affected deployments were identified via FOFA. This can lead to full system compromise, data theft, or service disruption.
Recommendations Update to version 1.9.2. As a temporary workaround, disable the Shareable Playground feature to prevent unauthenticated access to the vulnerable endpoint.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48519
GHSA-V5FF-9Q35-Q26F
PYSEC-2026-243

Affected Products

Langflow