A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipulation leads to code injection. The attack needs to be performed locally. The vendor was contacted early about this disclosure but did not respond in any way.
References
| Link | Resource |
|---|---|
| https://github.com/dxz0069/softwareoverflow/blob/main/langflow_bundle_url_custom_component_startup_rce_vulndb.md | Exploit Mitigation Third Party Advisory |
| https://vuldb.com/cve/CVE-2026-12822 | Third Party Advisory VDB Entry |
| https://vuldb.com/submit/837582 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/372612 | Third Party Advisory VDB Entry |
| https://vuldb.com/vuln/372612/cti | Permissions Required VDB Entry |
| https://github.com/dxz0069/softwareoverflow/blob/main/langflow_bundle_url_custom_component_startup_rce_vulndb.md | Exploit Mitigation Third Party Advisory |
Configurations
History
26 Jun 2026, 13:35
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* | |
| References | () https://github.com/dxz0069/softwareoverflow/blob/main/langflow_bundle_url_custom_component_startup_rce_vulndb.md - Exploit, Mitigation, Third Party Advisory | |
| References | () https://vuldb.com/cve/CVE-2026-12822 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/submit/837582 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/372612 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/vuln/372612/cti - Permissions Required, VDB Entry | |
| First Time |
Langflow langflow
Langflow |
23 Jun 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/dxz0069/softwareoverflow/blob/main/langflow_bundle_url_custom_component_startup_rce_vulndb.md - |
22 Jun 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-22 00:16
Updated : 2026-06-26 13:35
NVD link : CVE-2026-12822
Mitre link : CVE-2026-12822
CVE.ORG link : CVE-2026-12822
JSON object : View
Products Affected
langflow
- langflow
