Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
Medium6.1CVE-2026-48520 · Published Jun 16, 2026 · updated Jul 20, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| langflow PyPI | < 1.10.0 | 1.10.0 |
Details and references
### Summary The "Shareable Playground" (or "Public Flows" in code) contains a potential arbitrary file-read vulnerability, depending on the exact flow configuration used. By making a flow public, public execution of the flow is allowed. The execution request can contain a list of files that gets read by Langflow and fed into the LLM. The files path can be any path supported by the storage - it can be either a local file or *S3 path* if supported by the local configuration ### Details Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link. Specifically, it enables the route `/api/v1/build_public_tmp` to execute any public flow, given a public flow ID. This request contains a `files` field that can contain a list of files. The files get read in `LCModelComponent._get_chat_result` in a call to `to_lc_message`. A detailed stacktrace: ``` ... File "/Users/ori/Work/research/langchain/langflow/src/backend/base/langflow/api/build.py", line 466, in build_vertices vertex_build_response: VertexBuildResponse = await _build_vertex(vertex_id, graph, event_manager) File "/Users/ori/Work/research/langchain/langflow/src/backend/base/langflow/api/build.py", line 324, in _build_vertex vertex_build_result = await graph.build_vertex( File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/graph/graph/base.py", line 1563, in build_vertex await vertex.build( File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/graph/vertex/base.py", line 770, in build await step(user_id=user_id, event_manager=event_manager, **kwargs) File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/events/observability/lifecycle_events.py", line 95, in wrapper result = await observed_method(self, *args, **kwargs) File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/graph/vertex/base.py", line 411, in _build await self._build_results( File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/graph/vertex/base.py", line 640, in _build_results result = await initialize.loading.get_instance_results( File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/interface/initialize/loading.py", line 76, in get_instance_results return await build_component(params=custom_params, custom_component=custom_component) File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/interface/initialize/loading.py", line 299, in build_component build_results, artifacts = await custom_component.build_results() File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/custom/custom_component/component.py", line 1136, in build_results return await self._build_with_tracing() File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/custom/custom_component/component.py", line 1118, in _build_with_tracing results, artifacts = await self._build_results() File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/custom/custom_component/component.py", line 1163, in _build_results result = await self._get_output_result(output) File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/custom/custom_component/component.py", line 1238, in _get_output_result result = await method() if inspect.iscoroutinefunction(method) else await asyncio.to_thread(method) File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/base/models/model.py", line 88, in text_response result = await self.get_chat_result( File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/base/models/model.py", line 180, in get_chat_result return await self._get_chat_result( File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/base/models/model.py", line 232, in _get_chat_result messages.append(input_value.to_lc_message(self.name)) File "/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/schema/message.py", line 184, in to_lc_message file_conte
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-73
- Also known as
- CVE-2026-48520, PYSEC-2026-244
More Langflow advisories
All Langflow| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 16 | Langflow: IDOR/BOLA in Monitor API , Missing Ownership Enforcement on 7 Endpoints CVE-2026-33760High8.8fixed in 1.9.0 | High8.8 | 1.9.0 |
| Jun 16 | Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint CVE-2026-42867Medium6.5fixed in 1.9.0 | Medium6.5 | 1.9.0 |
| Jun 16 | Langflow: Unauthenticated RCE in Shareable Playgrounds CVE-2026-48519Critical9.6fixed in 1.9.2 | Critical9.6 | 1.9.2 |
| Jun 17 | Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak CVE-2026-55450Critical9.3fixed in 1.9.1 | Critical9.3 | 1.9.1 |
| Jun 19 | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow CVE-2026-55255High8.4fixed in 1.9.1 | High8.4 | 1.9.1 |
| Jun 19 | Langflow: Logout button does not clear session CVE-2026-55423Medium6.1fixed in 1.7.0 | Medium6.1 | 1.7.0 |