¡¾·ì϶¹«¸æ¡¿Langflow CSV Agent Ô¶³Ì´úÂëÖ´Ðзì϶(CVE-2026-27966)
°ä²¼¹¦·ò 2026-02-27Ò»¡¢·ì϶¸ÅÊö
·ìϼûû³Æ | Langflow CSV Agent Ô¶³Ì´úÂëÖ´Ðзì϶ | ||
CVE ID | CVE-2026-27966 | ||
·ì϶ÀàÐÍ | RCE | ·¢ÏÖ¹¦·ò | 2026-2-27 |
·ì϶ÆÀ·Ö | 9.8 | ·ì϶µÈ¼¶ | ÑϳÁ |
¹¥»÷ÏòÁ¿ | ÍøÂç | ËùÐèȨÏÞ | ÎÞ |
ÀûÓÃÄÑ¶È | µÍ | Óû§½»»¥ | ²»±ØÒª |
PoC/EXP | Òѹ«¿ª | ÔÚÒ°ÀûÓà | δ·¢ÏÖ |
LangflowÊÇ»ùÓÚLangChain¹¹½¨µÄ¿ÉÊÓ»¯´ó˵»°Ä£Ð͹¤×÷Á÷±àÅŹ¤¾ß£¬Ö§³Öͨ¹ýÍÏ×§·½Ê½´î½¨´úÀí¡¢¹¤¾ßºÍÊý¾Ý´¦ÖÃÁ÷³Ì£¬±ãÓÚ¼±¾ç¿ª·¢Óë²âÊÔLLMÀûÓá£ÆäÌṩ½Úµã»¯×é¼þÖÎÀí¡¢API¼¯³É¼°¶àÄ£ÐÍÖ§³Ö£¬ºÏÓÃÓÚÔÐÍÑéÖ¤Óë³ö²ú²¿Ê𳡾°¡£
¶þ¡¢Ó°ÏìÁìÓò
Langflow < 1.6.9
Èý¡¢°²È«´ëÊ©
3.1 Éý¼¶°æ±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/langflow-ai/langflow/releases/
3.2 һʱ´ëÊ©
ÔÝÎÞ¡£


¾©¹«Íø°²±¸11010802024551ºÅ