{"id":"CVE-2026-48520","aliases":["GHSA-rcjh-r59h-gq37","PYSEC-2026-244"],"url":"https://o3.security/vulnerability/CVE-2026-48520","summary":"Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read","details":"Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the \"Shareable Playground\" (or \"Public Flows\" in code) contains a potential arbitrary file-read vulnerability, depending on the exact flow configuration used. By making a flow public, public execution of the flow is allowed. The execution request can contain a list of files that gets read by Langflow and fed into the LLM. The files path can be any path supported by the storage - it can be either a local file or S3 path if supported by the local configuration This vulnerability is fixed in 1.10.0.","published":"2026-06-23T16:31:27.362Z","modified":"2026-08-12T03:51:24.984824519Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N"},"epss":{"score":0.00437,"percentile":0.36396,"asOf":"2026-08-27"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"langflow","fixedVersion":"1.10.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48520.json"},{"type":"ADVISORY","url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-rcjh-r59h-gq37"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48520"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:24.984824519Z"}}