SB2026061114 - Information disclosure in Langflow
Published: June 11, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) External Control of File Name or Path (CVE-ID: CVE-2026-48520)
CWE-ID: CWE-73 - External Control of File Name or Path
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to external control of file name or path in the Shareable Playground public flow execution route and file handling logic when processing a crafted files list in requests to /api/v1/build_public_tmp. A remote attacker can send a specially crafted request containing arbitrary local or S3 file paths to disclose sensitive information.
Exploitation requires the Shareable Playground feature to be enabled for a public flow, and reading the file contents back depends on the specific LLM configuration.
Remediation
Install update from vendor's website.