9.6
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Description
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All components based on BaseFileComponent are vulnerable to the vulnerability. This includes Docling (DoclingInlineComponent), Docling Serve, DoclingRemoteComponent), Read File (FileComponent), NVIDIA Retriever Extraction (NvidiaIngestComponent), Video File (VideoFileComponent), and Unstructured API (UnstructuredComponent). This vulnerability is fixed in 1.9.2.
AI Analysis
Arbitrary file read vulnerability with potential RCE exploit in Langflow BaseFileComponent-based nodes
Basic Information
ID
CVE-2026-55447
Source
GitHub_M
Published
Jun 23, 2026 at 16:21
Affected Product
Vendor
langflow-ai
Product
langflow
Version
< 1.9.2
Affected Versions
langflow-ai langflow < 1.9.2
CWE Classification
AI Assessment
AI Score
9.6 / 10
AI Severity
Critical
Vendor
Langflow AI
Product
Langflow
Version
< 1.9.2