CVE Explorer
CVE-2026-55450
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow. This can lead to space exhaustion on the server. In addition, in the response, the absolute path of the uploaded file is reported to the attacker, which is an information leak that can assist in chaining other primitives. This vulnerability is fixe
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:88a29327eb9ecbbfe439b3f8ec2e35151b16997af627d96632ce989d7d5ffe5b · sha256:56191f6f7ef92cca… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:88a29327eb9ecbbfe439b3f8ec2e35151b16997af627d96632ce989d7d5ffe5b · sha256:56191f6f7ef92cca… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-400","description":"CWE-400: Uncontrolled Resource Consumption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:88a29327eb9ecbbfe439b3f8ec2e35151b16997af627d96632ce989d7d5ffe5b · sha256:56191f6f7ef92cca… · /containers/cna/problemTypes/2/descriptions/0
Affected products and versions
1 source assertion{"product":"langflow","vendor":"langflow-ai","versions":[{"status":"affected","version":"< 1.9.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:88a29327eb9ecbbfe439b3f8ec2e35151b16997af627d96632ce989d7d5ffe5b · sha256:56191f6f7ef92cca… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.3,"baseSeverity":"CRITICAL","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:88a29327eb9ecbbfe439b3f8ec2e35151b16997af627d96632ce989d7d5ffe5b · sha256:56191f6f7ef92cca… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
3 source assertions{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:88a29327eb9ecbbfe439b3f8ec2e35151b16997af627d96632ce989d7d5ffe5b · sha256:56191f6f7ef92cca… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-200","description":"CWE-200: Exposure of Sensitive Information to an Unauthorized Actor","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:88a29327eb9ecbbfe439b3f8ec2e35151b16997af627d96632ce989d7d5ffe5b · sha256:56191f6f7ef92cca… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-400","description":"CWE-400: Uncontrolled Resource Consumption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:88a29327eb9ecbbfe439b3f8ec2e35151b16997af627d96632ce989d7d5ffe5b · sha256:56191f6f7ef92cca… · /containers/cna/problemTypes/2/descriptions/0
Source references
3 source assertions{"name":"https://github.com/langflow-ai/langflow/pull/12831","tags":["x_refsource_MISC"],"url":"https://github.com/langflow-ai/langflow/pull/12831"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:88a29327eb9ecbbfe439b3f8ec2e35151b16997af627d96632ce989d7d5ffe5b · sha256:56191f6f7ef92cca… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-x223-p2gf-v735"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:88a29327eb9ecbbfe439b3f8ec2e35151b16997af627d96632ce989d7d5ffe5b · sha256:56191f6f7ef92cca… · /containers/adp/0/references/0
{"name":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-x223-p2gf-v735","tags":["x_refsource_CONFIRM"],"url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-x223-p2gf-v735"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:88a29327eb9ecbbfe439b3f8ec2e35151b16997af627d96632ce989d7d5ffe5b · sha256:56191f6f7ef92cca… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.