/Vulnerability Library

Langflow <= 1.8.4 - Path Traversal to RCE via File Upload

CVE-2026-5027
Verified

Description

The application contains a path traversal vulnerability caused by unsanitized 'filename' parameter in the 'POST /api/v2/files' multipart form data, letting attackers write files to arbitrary filesystem locations, exploit requires crafted request.

Severity

High

CVSS Score

8.8

Exploit Probability

5%

Affected Product

langflow

Published Date

June 9, 2026

Template Author

pussycat0x

CVE-2026-5027.yaml
8.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-5027
CWE ID:
cwe-22

References

https://github.com/langflow-ai/langflow/pull/12227https://github.com/0xBlackash/CVE-2026-5027https://github.com/langflow-ai/langflow/security/advisories/GHSA-g2j9-7rj2-gm6c

Remediation Steps

Sanitize the 'filename' parameter to prevent path traversal or update to the latest secure version.