External Control of File Name or Path in Langflow - CVE-2026-48520
Published: June 11, 2026
Langflow
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to external control of file name or path in the Shareable Playground public flow execution route and file handling logic when processing a crafted files list in requests to /api/v1/build_public_tmp. A remote attacker can send a specially crafted request containing arbitrary local or S3 file paths to disclose sensitive information.
Exploitation requires the Shareable Playground feature to be enabled for a public flow, and reading the file contents back depends on the specific LLM configuration.