CVE-2026-55447Langflow · Langflow
Vulnerability data via NVD (ingested)
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All components based on BaseFileComponent are vulnerable to the vulnerability. This includes Docling (DoclingInlineComponent), Docling Serve, DoclingRemoteComponent), Read File (FileComponent), NVIDIA Retriever Extraction (NvidiaIngestComponent), Video File (VideoFileComponent), and Unstructured API (UnstructuredComponent). This vulnerability is fixed in 1.9.2.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-55447product:"Langflow Langflow"http.html:"Langflow"More intel sources (5)
vuln:CVE-2026-55447vulnerabilities.cve_id: CVE-2026-55447CVE-2026-55447CVE-2026-55447"CVE-2026-55447" exploit -site:nvd.nist.gov