Sploitus

CVE-2026-5027

5 known exploits for CVE-2026-5027

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

Affected products
Api/V2/Files
Langflow
< 1.9.0
CVSS 3.1
8.8 HIGH
EPSS
33.3% (98th percentile)
Weakness
CWE-22
NVD status
Analyzed
Published
2026-03-27
CVE-2026-5027 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2026-5027

Proof-of-concept code and exploit modules indexed by Sploitus