SB2026061114 - Information disclosure in Langflow



SB2026061114 - Information disclosure in Langflow

Published: June 11, 2026

Security Bulletin ID SB2026061114
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) External Control of File Name or Path (CVE-ID: CVE-2026-48520)

CWE-ID: CWE-73 - External Control of File Name or Path

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to external control of file name or path in the Shareable Playground public flow execution route and file handling logic when processing a crafted files list in requests to /api/v1/build_public_tmp. A remote attacker can send a specially crafted request containing arbitrary local or S3 file paths to disclose sensitive information.

Exploitation requires the Shareable Playground feature to be enabled for a public flow, and reading the file contents back depends on the specific LLM configuration.


Remediation

Install update from vendor's website.