<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 17:16:10 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-329898</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329898</link>
      <description>EUVD-2026-329898</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329898</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55447</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55447</link>
      <description>&lt;p&gt;Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All components based on BaseFileComponent are vulnerable to the vulnerability. This includes Docling (DoclingInlineComponent), Docling Serve, DoclingRemoteComponent), Read File (FileComponent), NVIDIA Retriever Extraction (NvidiaIngestComponent), Video File (VideoFileComponent), and Unstructured API (UnstructuredComponent). This vulnerability is fixed in 1.9.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All components based on BaseFileComponent are vulnerable to the vulnerability. This includes Docling (DoclingInlineComponent), Docling Serve, DoclingRemoteComponent), Read File (FileComponent), NVIDIA Retriever Extraction (NvidiaIngestComponent), Video File (VideoFileComponent), and Unstructured API (UnstructuredComponent). This vulnerability is fixed in 1.9.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55447</guid>
    </item>
    <item>
      <title>GHSA-ccv6-r384-xp75 — Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-ccv6-r384-xp75</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;### Summary
All components based on `BaseFileComponent` are vulnerable to the following vulnerability:
1. Docling (`DoclingInlineComponent`)
2. Docling Serve (`DoclingRemoteComponent`)
3. Read File (`FileComponent`)
4. NVIDIA Retriever Extraction (`NvidiaIngestComponent`)
5. Video File (`VideoFileComponent`)
6. Unstructured API (`UnstructuredComponent`)&lt;/p&gt;
&lt;p&gt;For clarity, from now on I&amp;#39;ll only refer to Read File component.&lt;/p&gt;
&lt;p&gt;The Read File node processes user-controlled files.
Example scenario is a RAG chatbot - a system that allows users of an organization to ask questions about documents saved in the organizations.&lt;/p&gt;
&lt;p&gt;By controlling a files that are digested into the RAG, an attacker can direct the node to read *any* file on the file-system by absolute path.&lt;/p&gt;
&lt;p&gt;Using this vulnerability an attacker can acheive RCE:
1. Upload a file that directs the node to read Langflow&amp;#39;s `secret_key` file containing the JWT token secret.
2. This would allow the attacker then to simply task the Chatbot for the JWT secret.
3. Using this secret, the attacker then crafts a JWT token for any user-id, bypassing authentication.
4. Code execution is then trivial - simply create a new flow with &amp;#34;Python Interpreter&amp;#34; node, fill it with arbitrary Python code and execute it.&lt;/p&gt;
&lt;p&gt;Tested on commit 2d67402b1dbaefcbce85a244d4a6cd5e4bda1cfe&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability is in:
`langflow/src/lfx/src/lfx/base/data/base_file.py`
Specifically in `_unpack_bundle`. This function extracts tar files, which can contain a symlink…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;### Summary
All components based on `BaseFileComponent` are vulnerable to the following vulnerability:
1. Docling (`DoclingInlineComponent`)
2. Docling Serve (`DoclingRemoteComponent`)
3. Read File (`FileComponent`)
4. NVIDIA Retriever Extraction (`NvidiaIngestComponent`)
5. Video File (`VideoFileComponent`)
6. Unstructured API (`UnstructuredComponent`)&lt;/p&gt;
&lt;p&gt;For clarity, from now on I&amp;#39;ll only refer to Read File component.&lt;/p&gt;
&lt;p&gt;The Read File node processes user-controlled files.
Example scenario is a RAG chatbot - a system that allows users of an organization to ask questions about documents saved in the organizations.&lt;/p&gt;
&lt;p&gt;By controlling a files that are digested into the RAG, an attacker can direct the node to read *any* file on the file-system by absolute path.&lt;/p&gt;
&lt;p&gt;Using this vulnerability an attacker can acheive RCE:
1. Upload a file that directs the node to read Langflow&amp;#39;s `secret_key` file containing the JWT token secret.
2. This would allow the attacker then to simply task the Chatbot for the JWT secret.
3. Using this secret, the attacker then crafts a JWT token for any user-id, bypassing authentication.
4. Code execution is then trivial - simply create a new flow with &amp;#34;Python Interpreter&amp;#34; node, fill it with arbitrary Python code and execute it.&lt;/p&gt;
&lt;p&gt;Tested on commit 2d67402b1dbaefcbce85a244d4a6cd5e4bda1cfe&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability is in:
`langflow/src/lfx/src/lfx/base/data/base_file.py`
Specifically in `_unpack_bundle`. This function extracts tar files, which can contain a symlink…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-ccv6-r384-xp75</guid>
    </item>
    <item>
      <title>PYSEC-2026-378 — Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-378</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;### Summary
All components based on `BaseFileComponent` are vulnerable to the following vulnerability:
1. Docling (`DoclingInlineComponent`)
2. Docling Serve (`DoclingRemoteComponent`)
3. Read File (`FileComponent`)
4. NVIDIA Retriever Extraction (`NvidiaIngestComponent`)
5. Video File (`VideoFileComponent`)
6. Unstructured API (`UnstructuredComponent`)&lt;/p&gt;
&lt;p&gt;For clarity, from now on I&amp;#39;ll only refer to Read File component.&lt;/p&gt;
&lt;p&gt;The Read File node processes user-controlled files.
Example scenario is a RAG chatbot - a system that allows users of an organization to ask questions about documents saved in the organizations.&lt;/p&gt;
&lt;p&gt;By controlling a files that are digested into the RAG, an attacker can direct the node to read *any* file on the file-system by absolute path.&lt;/p&gt;
&lt;p&gt;Using this vulnerability an attacker can acheive RCE:
1. Upload a file that directs the node to read Langflow&amp;#39;s `secret_key` file containing the JWT token secret.
2. This would allow the attacker then to simply task the Chatbot for the JWT secret.
3. Using this secret, the attacker then crafts a JWT token for any user-id, bypassing authentication.
4. Code execution is then trivial - simply create a new flow with &amp;#34;Python Interpreter&amp;#34; node, fill it with arbitrary Python code and execute it.&lt;/p&gt;
&lt;p&gt;Tested on commit 2d67402b1dbaefcbce85a244d4a6cd5e4bda1cfe
 
### Details
The vulnerability is in:
`langflow/src/lfx/src/lfx/base/data/base_file.py`
 Specifically in `_unpack_bundle`. This function extracts tar files, which can contain a symli…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;### Summary
All components based on `BaseFileComponent` are vulnerable to the following vulnerability:
1. Docling (`DoclingInlineComponent`)
2. Docling Serve (`DoclingRemoteComponent`)
3. Read File (`FileComponent`)
4. NVIDIA Retriever Extraction (`NvidiaIngestComponent`)
5. Video File (`VideoFileComponent`)
6. Unstructured API (`UnstructuredComponent`)&lt;/p&gt;
&lt;p&gt;For clarity, from now on I&amp;#39;ll only refer to Read File component.&lt;/p&gt;
&lt;p&gt;The Read File node processes user-controlled files.
Example scenario is a RAG chatbot - a system that allows users of an organization to ask questions about documents saved in the organizations.&lt;/p&gt;
&lt;p&gt;By controlling a files that are digested into the RAG, an attacker can direct the node to read *any* file on the file-system by absolute path.&lt;/p&gt;
&lt;p&gt;Using this vulnerability an attacker can acheive RCE:
1. Upload a file that directs the node to read Langflow&amp;#39;s `secret_key` file containing the JWT token secret.
2. This would allow the attacker then to simply task the Chatbot for the JWT secret.
3. Using this secret, the attacker then crafts a JWT token for any user-id, bypassing authentication.
4. Code execution is then trivial - simply create a new flow with &amp;#34;Python Interpreter&amp;#34; node, fill it with arbitrary Python code and execute it.&lt;/p&gt;
&lt;p&gt;Tested on commit 2d67402b1dbaefcbce85a244d4a6cd5e4bda1cfe
 
### Details
The vulnerability is in:
`langflow/src/lfx/src/lfx/base/data/base_file.py`
 Specifically in `_unpack_bundle`. This function extracts tar files, which can contain a symli…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-378</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2030 — Langflow: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2030</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Langflow ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Langflow ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2030</guid>
    </item>
  </channel>
</rss>
