CVE-2026-55447Disclosure(langflow / langflow)

MEDIUMCVSS 9.6 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch langflow langflow systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All components based on BaseFileComponent are vulnerable to the vulnerability. This includes Docling (DoclingInlineComponent), Docling Serve, DoclingRemoteComponent), Read File (FileComponent), NVIDIA Retriever Extraction (NvidiaIngestComponent), Video File (VideoFileComponent), and Unstructured API (UnstructuredComponent). This vulnerability is fixed in 1.9.2.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61CWE-200

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-06-23); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-23: 2Mentions · 2026-06-26: 1Mentions · 2026-07-17: 1Active Exploitation · 2026-07-17: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-26: 1Technical Details · 2026-07-17: 106-2306-2607-17
Signal classification4 categories
Disclosure
125.0%
General
125.0%
Patch
125.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-232
Disclosure1General1
2026-06-261
Patch1
2026-07-171
Active Exploitation1
Full discourse4 posts
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Three critical Langflow security vulnerabilities (CVE-2026-55255, CVE-2026-55447, CVE-2026-55450) expose AI applications to RCE and DoS attacks. Patch now. #Langflow #Vulnerability #CyberSecurity #CVE #AppSec https://securityonline.info/langflow-security-vulnerabilities https://t.co/9eNzB5fdOy

    Post summary

    Three critical Langflow CVEs have been announced, exposing RCE and DoS risks; users are urged to apply patches immediately.

    00020474
    12.8K followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Active Exploitation

    CVE-2026-55447 is live. If you run pip langflow, read this now. Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit Stay ahead of the curve.

    Post summary

    CVE-2026-55447 is actively exploited in Langflow, enabling arbitrary file read leading to RCE. No patch or workaround is mentioned.

    0000063
    341 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-55447 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can … https://www.cve.org/CVERecord?id=CVE-2026-55447 ----- Traducción: CVE-2026-55447 Lan… http://infoflow.cloud`

    Post summary

    CVE-2026-55447 in Langflow permits attackers to manipulate files processed by the RAG pipeline before version 1.9.2, but the post provides limited detail and no evidence of PoC, exploitation, or patch availability.

    0000033
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-55447 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can … https://www.cve.org/CVERecord?id=CVE-2026-55447

    Post summary

    This tweet announces CVE-2026-55447 against Langflow, noting that prior to v1.9.2, attackers can exploit file ingestion into the RAG system; no PoC, exploit, patch, or active exploitation details are provided.

    00000669
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more