Vulnerability
Published 2026-03-27
Verified 2026-09-01

Langflow path traversal to arbitrary file write and RCE (CVE-2026-5027)

Tenable's advisory says Langflow's POST /api/v2/files endpoint does not sanitise multipart filenames, allowing a logged-in attacker to use path traversal to write files outside the upload directory. The CNA rates it 8.8 (CVSS 3.1). Exploit-DB published a working exploit on 31 August for Langflow 1.8.4 and earlier that uses the default auto-login path, writes a cron file and reaches remote code execution; active-exploitation reporting also appeared on the wire. Upgrade to Langflow 1.9.0 or later. Disabling auto-login and restricting network access reduce exposure but do not fix the underlying arbitrary file write.

Product
Langflow
Versions
1.8.4 and earlier
CVSS
(CVSS 3.1, Tenable CNA)
Exploited in Australia?
unknown
Patch to
1.9.0 or later

Primary: Tenable Research TRA-2026-26 · Vendor: NVD / Tenable CNA · CVE: CVE-2026-5027 · Exploit-DB EDB-52659 (31 Aug 2026)

tech ai