CVE-2026-5026: falha de alta gravidade em langflow-ai langflow
Langflow - Stored XSS via Malicious SVG Upload
Publicada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7epss 0.3%
probabilidade de exploração
0.3%top 83% das CVEs
exploração observada
nãonenhuma fonte reporta
The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without sanitizing their content.
Since SVG files can contain embedded JavaScript, an attacker can upload a malicious SVG that executes arbitrary JavaScript when viewed by other users, leading to stored cross-site scripting (XSS). This allows stealing authentication tokens stored in cookies, including JWT access and refresh tokens.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Produtos afetados
langflow-ai · langflowCVEs relacionadas — langflow-ai langflow
No mesmo produto, das mais perigosas para as menos.
CVE-2025-3248CRITICALLangflow < 1.3.0 Unauthenticated RCE via /api/v1/validate/codeEPSS 100.0%KEVCVE-2026-33017CRITICALLangflow has Unauthenticated Remote Code Execution via Public Flow Build EndpointEPSS 24.8%KEVCVE-2026-55255HIGHLangflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's FlowEPSS 0.9%KEVCVE-2026-21445HIGHLangflow Missing Authentication on Critical API EndpointsEPSS 33.3%CVE-2025-68477HIGHLangflow vulnerable to Server-Side Request ForgeryEPSS 6.3%CVE-2025-68478HIGHLangflow Vulnerable to External Control of File Name or PathEPSS 5.8%