logo

Langflow File Upload Flaw: Details and PoC Exploit Publicly Disclosed (CVE-2026-55450)

ID: 473dbedb-13fa-5d6b-b56c-b726f2fb9fa5

STIX ID: report--473dbedb-13fa-5d6b-b56c-b726f2fb9fa5

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Do Son

...
...

A critical (CVSS 9.3) unauthenticated file-upload vulnerability (CVE-2026-55450) in Langflow versions prior to 1.9.1 lets attackers push unlimited data to servers causing disk exhaustion (DoS) and returns absolute file paths (information leak). A public proof-of-concept is available; maintainers patched the issue in 1.9.1 and administrators are advised to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.