<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T08:12:25.532446+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-48519</id>
    <title>CVE-2026-48519 — Langflow: Unauthenticated RCE in Shareable Playgrounds</title>
    <updated>2026-10-03T08:12:25.534211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> langflow-ai langflow</p>
<p>Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical RCE vulnerability. Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link. Specifically, it enables the route /api/v1/build_public_tmp to execute any public flow, given a public flow ID. When the route executes the flow, it allows for providing arbitrary custom Python code as the nodes code, inside the JSON payload. The vulnerable field is data.nodes[X].data.node.template.code.value. This vulnerability is fixed in 1.9.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-48519"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v5ff-9q35-q26f</id>
    <title>GHSA-v5ff-9q35-q26f — Langflow: Unauthenticated RCE in Shareable Playgrounds</title>
    <updated>2026-10-03T08:12:25.534266+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: langflow</p>
<p>### Summary
The "Shareable Playground" (or "Public Flows" in code) contains a critical RCE vulnerability.
Simply sharing a flow exposes the deployment to RCE risk by authenticated users.</p>
<p>Tested on commit 2d67402b1dbaefcbce85a244d4a6cd5e4bda1cfe</p>
<p>### Details
Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link.
Specifically, it enables the route `/api/v1/build_public_tmp` to execute any public flow, given a public flow ID.
When the route executes the flow, it allows for providing arbitrary custom Python code as the nodes code, inside the JSON payload!</p>
<p>The vulnerable field is data.nodes[X].data.node.template.code.value. See PoC for an example.</p>
<p>### PoC
Reproduction:
1. Create a new flow and add a Chat Input node to it
2. Share the flow ("Shareable Playground")
3. Access the public link with the browser developers tools open and execute the flow.
4. Find the `/api/v1/build_public_tmp` route and copy as cURL
5. Edit the `data.nodes[X].data.node.template.code.value` JSON field with any python code and run the cURL command.</p>
<p>Example PoC (replace flow ID with the correct one), and download [test_with_python.json](https://github.com/user-attachments/files/25159927/test_with_python.json):
```bash
curl 'http://localhost:7860/api/v1/build_public_tmp/&lt;flow-id&gt;/flow?start_component_id=ChatInput-syEJp&amp;log_builds=false&amp;event_delivery=streaming' \
  -H 'Content-Type: application/json' \
  -b 'client_id=anything' \
  --data…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v5ff-9q35-q26f"/>
  </entry>
</feed>
