SCA: security update for langflow (GHSA-g2j9-7rj2-gm6c)

critical Tenable Self-Hosted Container Security Plugin ID 439247

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Langflow is a tool for building and deploying AI-powered agents and workflows. Versions 1.2.0 through
1.8.1 have a bypass of the patch for CVE-2025-68478 (External Control of File Name), leading to the root
architectural issue within `LocalStorageService` remaining unresolved. Because the underlying storage
layer lacks boundary containment checks, the system relies entirely on the HTTP-layer `ValidatedFileName`
dependency. This defense-in-depth failure leaves the `POST /api/v2/files/` endpoint vulnerable to
Arbitrary File Write. The multipart upload filename bypasses the path-parameter guard, allowing
authenticated attackers to write files anywhere on the host system, leading to Remote Code Execution
(RCE). Version 1.9.0 contains an updated fix. (CVE-2026-33309)

Solution

Update the langflow library and its related packages to version 1.9.0 or later.

See Also

https://github.com/advisories/GHSA-g2j9-7rj2-gm6c

Plugin Details

Severity: Critical

ID: 439247

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 3/26/2026

Updated: 6/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7

Percentile: 98.33

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-33309

CVSS v3

Risk Factor: Critical

Base Score: 9.9

Temporal Score: 8.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/19/2026

Vulnerability Publication Date: 3/19/2026

Reference Information

CVE: CVE-2026-33309