<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 14:57:35 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-06918</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-06918</link>
      <description>bdu:2026-06918</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-06918</guid>
    </item>
    <item>
      <title>EUVD-2026-319935</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-319935</link>
      <description>EUVD-2026-319935</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-319935</guid>
    </item>
    <item>
      <title>fkie_cve-2026-33017</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33017</link>
      <description>&lt;p&gt;Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-33017</guid>
    </item>
    <item>
      <title>GHSA-vwmf-pq79-vjvx — Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vwmf-pq79-vjvx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `POST /api/v1/build_public_tmp/{flow_id}/flow` endpoint allows building public flows without requiring authentication. When the optional `data` parameter is supplied, the endpoint uses **attacker-controlled flow data** (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to `exec()` with zero sandboxing, resulting in unauthenticated remote code execution.&lt;/p&gt;
&lt;p&gt;This is distinct from CVE-2025-3248, which fixed `/api/v1/validate/code` by adding authentication. The `build_public_tmp` endpoint is **designed** to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code.&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;### Vulnerable Endpoint (No Authentication)&lt;/p&gt;
&lt;p&gt;**File:** `src/backend/base/langflow/api/v1/chat.py`, lines 580-657&lt;/p&gt;
&lt;p&gt;```python
@router.post(&amp;#34;/build_public_tmp/{flow_id}/flow&amp;#34;)
async def build_public_tmp(
    *,
    flow_id: uuid.UUID,
    data: Annotated[FlowDataRequest | None, Body(embed=True)] = None,  # ATTACKER CONTROLLED
    request: Request,
    # ... NO Depends(get_current_active_user) -- MISSING AUTH ...
):
    &amp;#34;&amp;#34;&amp;#34;Build a public flow without requiring authentication.&amp;#34;&amp;#34;&amp;#34;
    client_id = request.cookies.get(&amp;#34;client_id&amp;#34;)
    owner_user, new_flow_id = await verify_public_flow_and_get_user(flow_id=flow_id, client_id=client_id)&lt;/p&gt;
&lt;p&gt;job_id = await start_flow_build(
        flow_id=new_flow_id,
        data=data,  # Attacker&amp;#39;s data passed directl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `POST /api/v1/build_public_tmp/{flow_id}/flow` endpoint allows building public flows without requiring authentication. When the optional `data` parameter is supplied, the endpoint uses **attacker-controlled flow data** (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to `exec()` with zero sandboxing, resulting in unauthenticated remote code execution.&lt;/p&gt;
&lt;p&gt;This is distinct from CVE-2025-3248, which fixed `/api/v1/validate/code` by adding authentication. The `build_public_tmp` endpoint is **designed** to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code.&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;### Vulnerable Endpoint (No Authentication)&lt;/p&gt;
&lt;p&gt;**File:** `src/backend/base/langflow/api/v1/chat.py`, lines 580-657&lt;/p&gt;
&lt;p&gt;```python
@router.post(&amp;#34;/build_public_tmp/{flow_id}/flow&amp;#34;)
async def build_public_tmp(
    *,
    flow_id: uuid.UUID,
    data: Annotated[FlowDataRequest | None, Body(embed=True)] = None,  # ATTACKER CONTROLLED
    request: Request,
    # ... NO Depends(get_current_active_user) -- MISSING AUTH ...
):
    &amp;#34;&amp;#34;&amp;#34;Build a public flow without requiring authentication.&amp;#34;&amp;#34;&amp;#34;
    client_id = request.cookies.get(&amp;#34;client_id&amp;#34;)
    owner_user, new_flow_id = await verify_public_flow_and_get_user(flow_id=flow_id, client_id=client_id)&lt;/p&gt;
&lt;p&gt;job_id = await start_flow_build(
        flow_id=new_flow_id,
        data=data,  # Attacker&amp;#39;s data passed directl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vwmf-pq79-vjvx</guid>
    </item>
    <item>
      <title>PYSEC-2026-379 — Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-379</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `POST /api/v1/build_public_tmp/{flow_id}/flow` endpoint allows building public flows without requiring authentication. When the optional `data` parameter is supplied, the endpoint uses **attacker-controlled flow data** (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to `exec()` with zero sandboxing, resulting in unauthenticated remote code execution.&lt;/p&gt;
&lt;p&gt;This is distinct from CVE-2025-3248, which fixed `/api/v1/validate/code` by adding authentication. The `build_public_tmp` endpoint is **designed** to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code.&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;### Vulnerable Endpoint (No Authentication)&lt;/p&gt;
&lt;p&gt;**File:** `src/backend/base/langflow/api/v1/chat.py`, lines 580-657&lt;/p&gt;
&lt;p&gt;```python
@router.post(&amp;#34;/build_public_tmp/{flow_id}/flow&amp;#34;)
 async def build_public_tmp(
    *,
    flow_id: uuid.UUID,
    data: Annotated[FlowDataRequest | None, Body(embed=True)] = None,  # ATTACKER CONTROLLED
    request: Request,
    # ... NO Depends(get_current_active_user) -- MISSING AUTH ...
):
    &amp;#34;&amp;#34;&amp;#34;Build a public flow without requiring authentication.&amp;#34;&amp;#34;&amp;#34;
    client_id = request.cookies.get(&amp;#34;client_id&amp;#34;)
    owner_user, new_flow_id = await verify_public_flow_and_get_user(flow_id=flow_id, client_id=client_id)&lt;/p&gt;
&lt;p&gt;job_id = await start_flow_build(
        flow_id=new_flow_id,
        data=data,  # Attacker&amp;#39;s data passed direct…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `POST /api/v1/build_public_tmp/{flow_id}/flow` endpoint allows building public flows without requiring authentication. When the optional `data` parameter is supplied, the endpoint uses **attacker-controlled flow data** (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to `exec()` with zero sandboxing, resulting in unauthenticated remote code execution.&lt;/p&gt;
&lt;p&gt;This is distinct from CVE-2025-3248, which fixed `/api/v1/validate/code` by adding authentication. The `build_public_tmp` endpoint is **designed** to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code.&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;### Vulnerable Endpoint (No Authentication)&lt;/p&gt;
&lt;p&gt;**File:** `src/backend/base/langflow/api/v1/chat.py`, lines 580-657&lt;/p&gt;
&lt;p&gt;```python
@router.post(&amp;#34;/build_public_tmp/{flow_id}/flow&amp;#34;)
 async def build_public_tmp(
    *,
    flow_id: uuid.UUID,
    data: Annotated[FlowDataRequest | None, Body(embed=True)] = None,  # ATTACKER CONTROLLED
    request: Request,
    # ... NO Depends(get_current_active_user) -- MISSING AUTH ...
):
    &amp;#34;&amp;#34;&amp;#34;Build a public flow without requiring authentication.&amp;#34;&amp;#34;&amp;#34;
    client_id = request.cookies.get(&amp;#34;client_id&amp;#34;)
    owner_user, new_flow_id = await verify_public_flow_and_get_user(flow_id=flow_id, client_id=client_id)&lt;/p&gt;
&lt;p&gt;job_id = await start_flow_build(
        flow_id=new_flow_id,
        data=data,  # Attacker&amp;#39;s data passed direct…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-379</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0747 — Langflow: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0747</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Langflow ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder beliebigen Code auszuführen, was weitere Angriffe ermöglicht.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Langflow ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder beliebigen Code auszuführen, was weitere Angriffe ermöglicht.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0747</guid>
    </item>
  </channel>
</rss>
