Sploitus

CVE-2025-68478

No indexed exploits for CVE-2025-68478 yet

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary path is specified in the request body's `fs_path`, the server serializes the Flow object into JSON and creates/overwrites a file at that path. There is no path restriction, normalization, or allowed directory enforcement, so absolute paths (e.g., /etc/poc.txt) are interpreted as is. Version 1.7.0 fixes the issue.

Affected products
Langflow
Langflow
< 1.7.0
Fix
Available
CVSS 3.1
7.1 HIGH
EPSS
3.8% (89th percentile)
Weakness
CWE-73, CWE-610
NVD status
Analyzed
Published
2025-12-19
CVE-2025-68478 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-68478 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-68478 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.