PatchSiren cyber security CVE debrief
CVE-2026-12822 langflow-ai CVE debrief
CVE-2026-12822 is a low-severity vulnerability in langflow-ai langflow up to 1.9.3. The issue affects an unknown function of the Bundle URL Loader component, allowing for code injection. The attack requires local access. The vendor, langflow-ai, was contacted but did not respond. Given the low CVSS score of 1.9, this issue has a relatively low priority posture. However, defenders should still assess their exposure and take steps to limit potential risks.
- Vendor
- langflow-ai
- Product
- langflow
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-22
- Original CVE updated
- 2026-06-26
- Advisory published
- 2026-06-22
- Advisory updated
- 2026-06-26
Who should care
Defenders responsible for systems using langflow-ai langflow up to 1.9.3 should assess their exposure to this vulnerability. Although the CVSS severity is low, local code injection can still pose risks, especially in environments with untrusted local users. Reviewing system configurations, ensuring proper access controls, and monitoring for suspicious activity are prudent steps.
Technical summary
The vulnerability CVE-2026-12822 affects langflow-ai langflow up to version 1.9.3. It is located in the Bundle URL Loader component and allows for code injection. The Common Vulnerabilities and Exposures (CVE) score is 1.9, indicating a low severity. The vulnerability is categorized under CWE-74 and CWE-94. The attack vector requires local access (AV:L), and the impact is limited (VC:L, VI:L, VA:L).
Defensive priority
Low priority due to local attack requirement and low CVSS score, but still requires attention in multi-user environments.
Recommended defensive actions
- Inventory systems using langflow-ai langflow up to 1.9.3 to assess exposure.
- Review and limit access to the Bundle URL Loader component.
- Monitor for suspicious activity indicating potential code injection attempts.
- Consider upgrading to a version beyond 1.9.3 if available.
- Review system configurations for proper access controls.
Evidence notes
The primary evidence for CVE-2026-12822 comes from Vuldb and NVD. The vulnerability affects langflow-ai langflow up to 1.9.3. Evidence limits suggest that the vendor did not respond to disclosure. Affected product/version/scope verification is needed from official sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12822 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12822
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12822 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12822
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/dxz0069/softwareoverflow/blob/main/langflow_bundle_url_custom_component_startup_rce_vulndb.md
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-12822
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/837582
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/372612
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/372612/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.