<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:08:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-329730</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329730</link>
      <description>EUVD-2026-329730</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329730</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48519</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48519</link>
      <description>&lt;p&gt;Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the &amp;#34;Shareable Playground&amp;#34; (or &amp;#34;Public Flows&amp;#34; in code) contains a critical RCE vulnerability. Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link. Specifically, it enables the route /api/v1/build_public_tmp to execute any public flow, given a public flow ID. When the route executes the flow, it allows for providing arbitrary custom Python code as the nodes code, inside the JSON payload. The vulnerable field is data.nodes[X].data.node.template.code.value. This vulnerability is fixed in 1.9.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the &amp;#34;Shareable Playground&amp;#34; (or &amp;#34;Public Flows&amp;#34; in code) contains a critical RCE vulnerability. Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link. Specifically, it enables the route /api/v1/build_public_tmp to execute any public flow, given a public flow ID. When the route executes the flow, it allows for providing arbitrary custom Python code as the nodes code, inside the JSON payload. The vulnerable field is data.nodes[X].data.node.template.code.value. This vulnerability is fixed in 1.9.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48519</guid>
    </item>
    <item>
      <title>GHSA-v5ff-9q35-q26f — Langflow: Unauthenticated RCE in Shareable Playgrounds</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v5ff-9q35-q26f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;### Summary
The &amp;#34;Shareable Playground&amp;#34; (or &amp;#34;Public Flows&amp;#34; in code) contains a critical RCE vulnerability.
Simply sharing a flow exposes the deployment to RCE risk by authenticated users.&lt;/p&gt;
&lt;p&gt;Tested on commit 2d67402b1dbaefcbce85a244d4a6cd5e4bda1cfe&lt;/p&gt;
&lt;p&gt;### Details
Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link.
Specifically, it enables the route `/api/v1/build_public_tmp` to execute any public flow, given a public flow ID.
When the route executes the flow, it allows for providing arbitrary custom Python code as the nodes code, inside the JSON payload!&lt;/p&gt;
&lt;p&gt;The vulnerable field is data.nodes[X].data.node.template.code.value. See PoC for an example.&lt;/p&gt;
&lt;p&gt;### PoC
Reproduction:
1. Create a new flow and add a Chat Input node to it
2. Share the flow (&amp;#34;Shareable Playground&amp;#34;)
3. Access the public link with the browser developers tools open and execute the flow.
4. Find the `/api/v1/build_public_tmp` route and copy as cURL
5. Edit the `data.nodes[X].data.node.template.code.value` JSON field with any python code and run the cURL command.&lt;/p&gt;
&lt;p&gt;Example PoC (replace flow ID with the correct one), and download [test_with_python.json](https://github.com/user-attachments/files/25159927/test_with_python.json):
```bash
curl &amp;#39;http://localhost:7860/api/v1/build_public_tmp/&amp;lt;flow-id&amp;gt;/flow?start_component_id=ChatInput-syEJp&amp;amp;log_builds=false&amp;amp;event_delivery=streaming&amp;#39; \
  -H &amp;#39;Content-Type: application/json&amp;#39; \
  -b &amp;#39;client_id=anything&amp;#39; \
  --data…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;### Summary
The &amp;#34;Shareable Playground&amp;#34; (or &amp;#34;Public Flows&amp;#34; in code) contains a critical RCE vulnerability.
Simply sharing a flow exposes the deployment to RCE risk by authenticated users.&lt;/p&gt;
&lt;p&gt;Tested on commit 2d67402b1dbaefcbce85a244d4a6cd5e4bda1cfe&lt;/p&gt;
&lt;p&gt;### Details
Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link.
Specifically, it enables the route `/api/v1/build_public_tmp` to execute any public flow, given a public flow ID.
When the route executes the flow, it allows for providing arbitrary custom Python code as the nodes code, inside the JSON payload!&lt;/p&gt;
&lt;p&gt;The vulnerable field is data.nodes[X].data.node.template.code.value. See PoC for an example.&lt;/p&gt;
&lt;p&gt;### PoC
Reproduction:
1. Create a new flow and add a Chat Input node to it
2. Share the flow (&amp;#34;Shareable Playground&amp;#34;)
3. Access the public link with the browser developers tools open and execute the flow.
4. Find the `/api/v1/build_public_tmp` route and copy as cURL
5. Edit the `data.nodes[X].data.node.template.code.value` JSON field with any python code and run the cURL command.&lt;/p&gt;
&lt;p&gt;Example PoC (replace flow ID with the correct one), and download [test_with_python.json](https://github.com/user-attachments/files/25159927/test_with_python.json):
```bash
curl &amp;#39;http://localhost:7860/api/v1/build_public_tmp/&amp;lt;flow-id&amp;gt;/flow?start_component_id=ChatInput-syEJp&amp;amp;log_builds=false&amp;amp;event_delivery=streaming&amp;#39; \
  -H &amp;#39;Content-Type: application/json&amp;#39; \
  -b &amp;#39;client_id=anything&amp;#39; \
  --data…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v5ff-9q35-q26f</guid>
    </item>
    <item>
      <title>PYSEC-2026-243</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-243</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the &amp;#34;Shareable Playground&amp;#34; (or &amp;#34;Public Flows&amp;#34; in code) contains a critical RCE vulnerability. Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link. Specifically, it enables the route /api/v1/build_public_tmp to execute any public flow, given a public flow ID. When the route executes the flow, it allows for providing arbitrary custom Python code as the nodes code, inside the JSON payload. The vulnerable field is data.nodes[X].data.node.template.code.value. This vulnerability is fixed in 1.9.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the &amp;#34;Shareable Playground&amp;#34; (or &amp;#34;Public Flows&amp;#34; in code) contains a critical RCE vulnerability. Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link. Specifically, it enables the route /api/v1/build_public_tmp to execute any public flow, given a public flow ID. When the route executes the flow, it allows for providing arbitrary custom Python code as the nodes code, inside the JSON payload. The vulnerable field is data.nodes[X].data.node.template.code.value. This vulnerability is fixed in 1.9.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-243</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1713 — Langflow: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1713</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Langflow ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Langflow ausnutzen, um beliebigen Programmcode auszuführen oder einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1713</guid>
    </item>
  </channel>
</rss>
