External Control of File Name or Path in Langflow - CVE-2026-48520

 

External Control of File Name or Path in Langflow - CVE-2026-48520

Published: June 11, 2026


Vulnerability identifier: #VU134291
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-48520
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Langflow
Affected software:
Langflow

Detailed vulnerability description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to external control of file name or path in the Shareable Playground public flow execution route and file handling logic when processing a crafted files list in requests to /api/v1/build_public_tmp. A remote attacker can send a specially crafted request containing arbitrary local or S3 file paths to disclose sensitive information.

Exploitation requires the Shareable Playground feature to be enabled for a public flow, and reading the file contents back depends on the specific LLM configuration.


How to mitigate CVE-2026-48520

Install security update from vendor's website.

Sources