CVE-2026-12822
גבוהה 7.8
תיאור (מקור, אנגלית)
A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipulation leads to code injection. The attack needs to be performed locally. The vendor was contacted early about this disclosure but did not respond in any way.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
1.9 (LOW)
מקור הציון: CNA
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-13/8/2026
- CWE
- CWE-74, CWE-94
מוצרים מושפעים
langflow: langflow
קישורים
- https://github.com/dxz0069/softwareoverflow/blob/main/langflow_bundle_url_cust… ExploitMitigationThird Party Advisory
- https://github.com/dxz0069/softwareoverflow/blob/main/langflow_bundle_url_cust… ExploitMitigationThird Party Advisory
- https://vuldb.com/cve/CVE-2026-12822 Third Party AdvisoryVDB Entry
- https://vuldb.com/submit/837582 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/372612 Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/372612/cti Permissions RequiredVDB Entry