BRIEFING NOTE - CVE-2026-6596 A critical file upload vulnerability exists in Langflow-AI's Langflow application up to version 1.1.0, specifically in the create_upload_file function within the API endpoint component. This flaw permits unrestricted file uploads to affected systems, allowing attackers to bypass intended access controls on the upload mechanism. The vulnerability carries a CVSS 3.1 score of 7.3 (HIGH), with a network-based attack vector requiring no special privileges or user interaction. The attack complexity is low, making exploitation straightforward. Successful exploitation could result in partial compromise of confidentiality, integrity, and availability across the affected system. The vulnerability is currently active on threat tracking lists and poses an elevated risk for exploitation. Public exploit code has been released, increasing the immediate threat to unpatched installations. Despite early vendor notification, the development team has not provided a response or patch, leaving users without an official remediation path. Organizations running Langflow 1.1.0 and earlier should treat this as a priority security concern and implement compensating controls or consider upgrading once patches become available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Langflow-Ai | Langflow | 1.0, 1.1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.