Vulnerability
Published 2026-03-27
Verified 2026-09-01
Langflow path traversal to arbitrary file write and RCE (CVE-2026-5027)
Tenable's advisory says Langflow's POST /api/v2/files endpoint does not sanitise multipart filenames, allowing a logged-in attacker to use path traversal to write files outside the upload directory. The CNA rates it 8.8 (CVSS 3.1). Exploit-DB published a working exploit on 31 August for Langflow 1.8.4 and earlier that uses the default auto-login path, writes a cron file and reaches remote code execution; active-exploitation reporting also appeared on the wire. Upgrade to Langflow 1.9.0 or later. Disabling auto-login and restricting network access reduce exposure but do not fix the underlying arbitrary file write.
- Product
- Langflow
- Versions
- 1.8.4 and earlier
- CVSS
- (CVSS 3.1, Tenable CNA)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- 1.9.0 or later
Primary: Tenable Research TRA-2026-26 · Vendor: NVD / Tenable CNA · CVE: CVE-2026-5027 · Exploit-DB EDB-52659 (31 Aug 2026)
