🛡️ CVE-2026-55447 — langflow

🔴 CVSS 9.5 — Critical ⚠️ Exploit Public CWE-200 OSV
9.5
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit

Summary

All components based on BaseFileComponent are vulnerable to the following vulnerability:

1. Docling (DoclingInlineComponent)

2. Docling Serve (DoclingRemoteComponent)

3. Read File (FileComponent)

4. NVIDIA Retriever Extraction (NvidiaIngestComponent)

5. Video File (VideoFileComponent)

6. Unstructured API (UnstructuredComponent)

For clarity, from now on I'll only refer to Read File component.

The Read File node processes user-controlled files.

Example scenario is a RAG chatbot - a system that allows users of an organization to ask questions about documents saved in the organizations.

By controlling a files that are digested into the RAG, an attacker can direct the node to read *any* file on the file-system by absolute path.

Using this vulnerability an attacker can acheive RCE:

1. Upload a file that directs the node to read Langflow's secret_key file containing the JWT token secret.

2. This would allow the attacker then to simply task the Chatbot for the JWT secret.

3. Using this secret, the attacker then crafts a JWT token for any user-id, bypassing authentication.

4. Code execution is then trivial - simply create a new flow with "Python Interpreter" node, fill it with arbitrary Python code and execute it.

Tested on commit 2d67402b1dbaefcbce85a244d4a6cd5e4bda1cfe

Details

The vulnerability is in:

langflow/src/lfx/src/lfx/base/data/base_file.py

Specifically in _unpack_bundle. This function extracts tar files, which can contain a symlink.

This symlink can point to any file in the filesystem. Then, in self.process_files(), the file pointed by the symlink will be parsed and saved into the RAG.

This can be done with unlimited number of symlinks in the same tar which can also be useful in some scenarios.

Suggestd fix - iterate over the files and make sure all are regular files or directories.

PoC

Reproduction:

1. Create a flow with Read File (or any other affected components), and connect its output to some storage such as Chroma DB.

2. Create a symlink pointing to any file. For the above exploit, point the symlink to langflow's JWT token file.

3. Compress this symlink with tar.

4. Upload it to the Read File component.

5. Check the database, or ask a Chatbot connected to this vector database for the contents of the file.

Concrete PoC:

------------

  • Flow with RAG ingestion and a Chatbot around it: [Vector Store RAG.json](https://github.com/user-attachments/files/25159960/Vector.Store.RAG.json)
  • Exploit tar: [archive.tar.txt](https://github.com/user-attachments/files/25159954/archive.tar.txt) (remove .txt, GitHub blocked .tar)
  • Create a file /tmp/trip.docx with any contents in it
  • Ingest the file in the flow above, and ask the Chatbot a question about this file.

A demo showing the attack:

https://github.com/user-attachments/assets/af00f700-f13f-4eac-848e-8afd11fb9297

In the demo the attacker steals Langflow secret key used to sign JWTs. The second stage of the attack, not shown in the demo, is using this key to sign a JWT token and executing Python code on the server using the Python code interpreter node.

Impact

Any Langflow user using any of the above mentioned components to ingest user-controlled data is affected. Depending on exact scenario, the user can also be exposed to an RCE risk.

Patches

Fixed in 1.9.2 via PR [#12945](https://github.com/langflow-ai/langflow/pull/12945). BaseFileComponent._unpack_bundle now rejects symlink and hardlink members (and any non-regular entries) during TAR extraction, with additional defensive symlink filtering during directory recursion and after extraction. Upgrade to 1.9.2 or later.

Ori Lahav

Security Researcher @ Rubrik Inc.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. A user must be tricked into taking some action. The scope is changed, meaning a successful attack can affect components beyond the vulnerable one. Rated impact: confidentiality high, integrity high, availability high.

Weakness class

CVE-2026-55447 is classified as CWE-200: Exposure of Sensitive Information. Information that should stay internal is disclosed to someone who is not authorised to see it.

Affected software

CVE-2026-55447 is recorded against 1 package.

  • langflow (fixed in 1.9.2)

Timeline and source

Published on 19 June 2026 and last revised on 1 July 2026. A public exploit is known to exist, which raises the urgency of patching considerably. A vendor advisory or fix has been published. Record sourced from OSV.

References

github.com (Web)
github.com (Web)
github.com (Package)

Details

Severity CRITICAL
CVSS Score 9.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE CWE-200
Public Exploit ⚠️ Yes
Source OSV
Published 2026-06-19
Updated 2026-08-12
Modified 2026-07-01

Affected Packages

Software From version Fixed in
langflow 1.9.2

Similar Threats

Exploit Protection

Are you running langflow?

CVE-2026-55447 carries CVSS 9.5 Critical rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2026-55447 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.