CVE-2026-5027: Langflow
High severity, CVSS 8.8. EPSS: 4.8% chance of exploitation in the next 30 days.
The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').
Affected products
- Langflow Langflow: before 1.9.0 (fixed in 1.9.0)
Published 2026-03-27. Last modified 2026-08-18.