security1 distinct publisher
Langflow's share button converts a saved flow into an unauthenticated code execution endpoint
CVE-2026-48519 lets anyone holding a shared Langflow playground link supply their own Python inside the build request. The exposure follows a user clicking share, so it lives in flow state rather than in server config.
Publishers:github.com
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap−10
- Incentives35
- Confidence