Executive brief
Langflow, a tool for building AI workflows, contains a critical security flaw in its 'Shareable Playground' feature. This feature is intended to let users share AI agents via a public link, but it inadvertently allows anyone with that link to run unauthorized commands on the server. An attacker could use this to take full control of the system, potentially stealing sensitive data or disrupting AI operations.
Technical details
A remote code execution (RCE) vulnerability exists in Langflow's 'Shareable Playground' (Public Flows) feature due to improper input validation of workflow payloads. The application exposes the `/api/v1/build_public_tmp` endpoint, which is designed to execute public flows for unauthenticated users. An attacker can provide a crafted JSON payload containing arbitrary Python code within the `data.nodes[X].data.node.template.code.value` field. When the server processes this request to build the graph and instantiate components, it executes the supplied Python code. This vulnerability is tracked as CVE-2026-48519 and is resolved in version 1.9.2.
Affected products
- langflow-ai Langflow < 1.9.2
Timeline
- 2026-05-27: advisory: Initial GitHub security advisory published
- 2026-06-23: disclosed: NVD publication date