CVE-2026-48519·Python vulnerability
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical RCE vulnerability. Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link. Specifically, it enables the route /api/v1/build_public_tmp to execute any public flow, given a public flow ID. When the route executes the flow, it allows for providing arbitrary custom Python code as the nodes code, inside the JSON payload. The vulnerable field is data.nodes[X].data.node.template.code.value. This vulnerability is fixed in 1.9.2.
- Severity
- critical
- Software
- Python
- Fixed in
- 1.9.2
- Published
- 2026-06-23
Affected versions
Until: 1.9.2
Fixed in: 1.9.2
How to fix this CVE
Upgrade Langflow to version 1.9.2 or later immediately to patch the remote code execution vulnerability in the Shareable Playground feature. This vulnerability allows unauthenticated attackers to execute arbitrary Python code through the public flow execution endpoint by injecting malicious code into workflow node templates. Apply the update across all Langflow instances, particularly those exposed to the internet.
sudo dnf update python3-langflow || pip3 install --upgrade langflow==1.9.2Defensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST /api/v1/build_public_tmp HTTP/1.1.*data\.nodes\[\d+\]\.data\.node\.template\.code\.value.*?(exec|subprocess|__import__|os\.system|eval|compile)WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block POST requests to /api/v1/build_public_tmp containing JSON payloads with patterns matching 'data.nodes[*].data.node.template.code.value' that include Python code execution keywords (exec, subprocess, __import__, os.system, eval, compile). Implement strict input validation requiring code templates to be from a whitelist of safe node types.How to check if you are affected
- Run 'langflow --version' or 'pip3 show langflow | grep Version' to check the installed Langflow version and confirm if it is below 1.9.2
- Verify if the Shareable Playground feature is enabled by checking the Langflow configuration file (typically in ~/.langflow/config.yaml or environment variables) for PUBLIC_FLOWS_ENABLED or similar settings
- Search application logs for POST requests to /api/v1/build_public_tmp with JSON payloads containing data.nodes[*].data.node.template.code.value fields; look for patterns like 'exec', 'subprocess', '__import__', or other code execution indicators
- After upgrading to 1.9.2+, re-run 'langflow --version' to confirm the patch version is installed, and review the API endpoint response to verify code injection validation is now in place
Indicators of compromise
- /api/v1/build_public_tmp
- data.nodes[X].data.node.template.code.value
- Langflow version < 1.9.2
FAQ
What is CVE-2026-48519?
CVE-2026-48519 is a critical remote code execution vulnerability in Langflow's Shareable Playground feature that allows unauthenticated users to execute arbitrary Python code by injecting malicious payloads into publicly accessible workflow nodes.
Is CVE-2026-48519 being actively exploited?
No, CVE-2026-48519 is not currently listed in the CISA KEV catalog and no public exploits are available, though the vulnerability severity warrants immediate patching due to its critical CVSS score of 9.6.
What versions of Python are affected by CVE-2026-48519?
The vulnerability affects all versions of Langflow prior to 1.9.2, regardless of the underlying Python version, though it requires Python 3.x for Langflow to run.
How do I check if my server is vulnerable to CVE-2026-48519?
Run 'pip3 show langflow' and check the Version field; if it is below 1.9.2, your installation is vulnerable. Additionally, verify that Shareable Playground is enabled in your Langflow configuration.
Does Defensia detect CVE-2026-48519?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Langflow is installed on a monitored server, CVE-2026-48519 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-48519. Free for 1 server.
Get started free