CVE-2026-5027
The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').
- Affected products
- Api/V2/Files
- Langflow
- < 1.9.0
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 33.3% (98th percentile)
- Weakness
- CWE-22
- NVD status
- Analyzed
- Published
- 2026-03-27
CVE-2026-5027 at NVD
5 known exploits for CVE-2026-5027
Proof-of-concept code and exploit modules indexed by Sploitus