CVE-2026-5027
CVSS 8.8 HIGH: the 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing… EPSS 5% (92º percentile).
Vulnerabilità ed exploit · Attacco ad app web
Langflow è un control plane per istanze di app AI, non solo un low-code builder, e questo difetto dà a uno sconosciuto un modo per scrivere sul server da una singola richiesta non autenticata. In pratica, la rottura della fiducia è nell'endpoint file: l'accesso anonimo ottiene una session per impostazione predefinita, e l'endpoint accetta un filename che non dovrebbe mai fidarsi del richiedente.
3 fonti · 11 giu
CVSS 8.8 HIGH: the 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing… EPSS 5% (92º percentile).
SecurityWeek
Hackers Exploit Langflow Vulnerability for Remote Code Execution
Disclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system.
originaleThe Hacker News
Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE
CVE-2026-5027 lets attackers abuse Langflow path traversal, exposing 7,000 AI app instances to file-write attacks.
originaleBleepingComputer
Path traversal flaw in AI dev platform Langflow exploited in attacks
Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in the AI development platform Langflow, to write arbitrary files on exposed servers.
originalePart of the PlainSec briefing for 2026-06-10
Every edition of this story: Bug di Langflow Trasforma AI Builder in Superficie di Scrittura sul Server