Langflow File Upload Flaw: Details and PoC Exploit Publicly Disclosed (CVE-2026-55450)
ID: 473dbedb-13fa-5d6b-b56c-b726f2fb9fa5
STIX ID: report--473dbedb-13fa-5d6b-b56c-b726f2fb9fa5
Feed Name: securityonline.info
Threat Score
A critical (CVSS 9.3) unauthenticated file-upload vulnerability (CVE-2026-55450) in Langflow versions prior to 1.9.1 lets attackers push unlimited data to servers causing disk exhaustion (DoS) and returns absolute file paths (information leak). A public proof-of-concept is available; maintainers patched the issue in 1.9.1 and administrators are advised to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
