{"id":"CVE-2026-48520","title":"Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read","summary":"Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read","severity":"medium","cvss":6.1,"cwe":["CWE-73"],"vendor":"langflow","product":"langflow","ecosystem":"pip","affected":["langflow < 1.10.0"],"patched":["langflow 1.10.0"],"published":"2026-06-16","updated":"2026-06-16","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-rcjh-r59h-gq37","references":[{"url":"https://github.com/langflow-ai/langflow/security/advisories/GHSA-rcjh-r59h-gq37"},{"url":"https://github.com/advisories/GHSA-rcjh-r59h-gq37"}],"tags":["ghsa","pip"],"epss":0.00437,"epssPercentile":0.37345,"ingestedAt":"2026-06-29T14:31:47.731Z","slug":"CVE-2026-48520","body":"## Overview\n\n### Summary\nThe \"Shareable Playground\" (or \"Public Flows\" in code) contains a potential arbitrary file-read vulnerability, depending on the exact flow configuration used.\n\nBy making a flow public, public execution of the flow is allowed. The execution request can contain a list of files that gets read by Langflow and fed into the LLM.\nThe files path can be any path supported by the storage - it can be either a local file or *S3 path* if supported by the local configuration\n\n### Details\nShareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link.\nSpecifically, it enables the route `/api/v1/build_public_tmp` to execute any public flow, given a public flow ID.\nThis request contains a `files` field that can contain a list of files. The files get read in `LCModelComponent._get_chat_result` in a call to `to_lc_message`. A detailed stacktrace:\n```\n...\n  File \"/Users/ori/Work/research/langchain/langflow/src/backend/base/langflow/api/build.py\", line 466, in build_vertices\n    vertex_build_response: VertexBuildResponse = await _build_vertex(vertex_id, graph, event_manager)\n  File \"/Users/ori/Work/research/langchain/langflow/src/backend/base/langflow/api/build.py\", line 324, in _build_vertex\n    vertex_build_result = await graph.build_vertex(\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/graph/graph/base.py\", line 1563, in build_vertex\n    await vertex.build(\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/graph/vertex/base.py\", line 770, in build\n    await step(user_id=user_id, event_manager=event_manager, **kwargs)\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/events/observability/lifecycle_events.py\", line 95, in wrapper\n    result = await observed_method(self, *args, **kwargs)\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/graph/vertex/base.py\", line 411, in _build\n    await self._build_results(\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/graph/vertex/base.py\", line 640, in _build_results\n    result = await initialize.loading.get_instance_results(\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/interface/initialize/loading.py\", line 76, in get_instance_results\n    return await build_component(params=custom_params, custom_component=custom_component)\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/interface/initialize/loading.py\", line 299, in build_component\n    build_results, artifacts = await custom_component.build_results()\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/custom/custom_component/component.py\", line 1136, in build_results\n    return await self._build_with_tracing()\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/custom/custom_component/component.py\", line 1118, in _build_with_tracing\n    results, artifacts = await self._build_results()\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/custom/custom_component/component.py\", line 1163, in _build_results\n    result = await self._get_output_result(output)\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/custom/custom_component/component.py\", line 1238, in _get_output_result\n    result = await method() if inspect.iscoroutinefunction(method) else await asyncio.to_thread(method)\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/base/models/model.py\", line 88, in text_response\n    result = await self.get_chat_result(\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/base/models/model.py\", line 180, in get_chat_result\n    return await self._get_chat_result(\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/base/models/model.py\", line 232, in _get_chat_result\n    messages.append(input_value.to_lc_message(self.name))\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/schema/message.py\", line 184, in to_lc_message\n    file_contents = self.get_file_content_dicts(model_name)\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/schema/message.py\", line 256, in get_file_content_dicts\n    content_dicts.append(create_image_content_dict(file, None, model_name))\n  File \"/Users/ori/Work/research/langchain/langflow/src/lfx/src/lfx/utils/image.py\", line 96, in create_image_content_dict\n    ...\n```\n\nThis triggers Langflow to feed the file into the LLM as an Image. Reading the files back depends on the specific LLM configuration.\n\n### PoC\nReproduction:\n1. Create a new flow and add a Chat Input node to it\n2. Share the flow (\"Shareable Playground\")\n3. Access the public link with the browser developers tools open and execute the flow.\n4. Find the `/api/v1/build_public_tmp` route and copy as cURL\n5. Edit the `files` JSON field to point to any file.\n\n### Impact\nPotential file read (local or S3) if shareable playground feature is used.\n\n\n\nOri Lahav\nSecurity Researcher @ Rubrik Inc.\n\n## Affected packages\n\n- `langflow < 1.10.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `langflow 1.10.0`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}