Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Multiple Langflow vulnerabilities: unauthenticated RCE, IDOR and path traversal

NVD published a batch of Langflow advisories covering flaws in the AI agent/workflow builder, including unauthenticated remote code execution via the "Shareable Playground" public flow route, IDOR issues letting authenticated users read, delete or execute other users' data and flows, path traversal and arbitrary file read, and a denial-of-service via unauthenticated file upload. All are fixed in releases between 1.0.19 and 1.10.0, and one IDOR (CVE-2026-55255) is listed in CISA's Known Exploited Vulnerabilities catalog.

Disclosed 23 June 2026 · Record updated 13 September 2026

Impact

Attackers could execute arbitrary Python code on Langflow servers without authentication, read or write arbitrary files, access, modify, delete or execute other users' flows and messages, and render the application unusable for all users.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33760
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42867
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48519
  4. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48520
  5. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55255
  6. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55423
  7. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55446
  8. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55447