Junglewise Threat Intelligence

CVE-2026-55450: Langflow unauthenticated file upload and path disclosure in upload endpoint

CVE-2026-55450 · Severity: critical · CVSS 9.3 · Published 2026-06-23

Technologies: Langflow-Ai Langflow, langflow (PyPI). Vendors: PyPI.

Executive brief

Langflow, a tool for building AI-powered workflows, contained a security flaw in a deprecated file upload feature. An unauthorized person could upload unlimited amounts of data to the server, potentially crashing the system by filling up its storage space. Additionally, the system would reveal the exact location of files on the server's hard drive, which could help an attacker plan further intrusions.

Technical details

A deprecated endpoint, POST /api/v1/upload/{flow_id}, lacked authentication and authorization checks (CWE-306). An unauthenticated attacker could send arbitrary data to this endpoint, which would be saved to the local filesystem without size limitations, leading to uncontrolled resource consumption (CWE-400) and potential Denial of Service (DoS). Furthermore, the API response included the absolute path of the uploaded file on the server, resulting in sensitive information disclosure (CWE-200). The vulnerability was addressed in version 1.9.1 by applying the 'get_flow' dependency to the route, which enforces both user authentication and flow-ownership verification.

Affected products

  • langflow-ai Langflow < 1.9.1

Timeline

  • 2026-04-22: patched: Fix merged in Pull Request #12831
  • 2026-06-17: advisory: GitHub Security Advisory GHSA-x223-p2gf-v735 published
  • 2026-06-23: disclosed: CVE-2026-55450 published to NVD

References

Related threats