Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6596

25
FAUCET Score

BRIEFING NOTE - CVE-2026-6596 A critical file upload vulnerability exists in Langflow-AI's Langflow application up to version 1.1.0, specifically in the create_upload_file function within the API endpoint component. This flaw permits unrestricted file uploads to affected systems, allowing attackers to bypass intended access controls on the upload mechanism. The vulnerability carries a CVSS 3.1 score of 7.3 (HIGH), with a network-based attack vector requiring no special privileges or user interaction. The attack complexity is low, making exploitation straightforward. Successful exploitation could result in partial compromise of confidentiality, integrity, and availability across the affected system. The vulnerability is currently active on threat tracking lists and poses an elevated risk for exploitation. Public exploit code has been released, increasing the immediate threat to unpatched installations. Despite early vendor notification, the development team has not provided a response or patch, leaving users without an official remediation path. Organizations running Langflow 1.1.0 and earlier should treat this as a priority security concern and implement compensating controls or consider upgrading once patches become available.

Impacted Technologies

VendorProductVersion(s)CPE
Langflow-AiLangflow
1.0, 1.1.0CNA affected

CVSS Data

CVSS version used by this source: 4.0

5.5MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
20.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 4th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

pippatch availablevia ghsa
Product: langflow-baseFixed in: 0.9.1

Vendor Advisories (1)

pipGHSA-vvfc-fp59-m92gmedium

Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API

Apr 20, 2026

References

gist.github.com / chenhouser2025/c2aabfdee41009cfe45d28a9924742a0
vuldb.com / submit/791919
vuldb.com / vuln/358231
vuldb.com / vuln/358231/cti