Sploitus

CVE-2026-42048

1 known exploit for CVE-2026-42048

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are concatenated directly into file paths without proper sanitization or boundary validation. An authenticated attacker can exploit this flaw to delete arbitrary directories anywhere on the server's filesystem, leading to data loss and potential service disruption. This vulnerability is fixed in 1.9.0.

Affected products
Langflow
Langflow
< 1.9.0
Fix
Available
CVSS 3.1
9.6 CRITICAL
EPSS
4.4% (91th percentile)
Weakness
CWE-22
NVD status
Analyzed
Published
2026-05-12
CVE-2026-42048 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-42048

Proof-of-concept code and exploit modules indexed by Sploitus