CVE-2026-5027
CVSS 8.8 HIGH: the 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing… EPSS 5% (92º percentile).
Vulnerabilità · 110 giorni fa
Langflow è un control plane per istanze di app AI, non solo un low-code builder, e questo difetto dà a uno sconosciuto un modo per scrivere sul server da una singola richiesta non autenticata. In pratica, la rottura della fiducia è nell'endpoint file: l'accesso anonimo ottiene una session per impostazione predefinita, e l'endpoint accetta un filename che non dovrebbe mai fidarsi del richiedente.
CVSS 8.8 HIGH: the 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing… EPSS 5% (92º percentile).
3 fonti che coprono questa storia
Hackers Exploit Langflow Vulnerability for Remote Code Execution
Disclosed in March, the security defect enables unauthenticated attackers to write files to arbitrary locations on the system.
Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE
CVE-2026-5027 lets attackers abuse Langflow path traversal, exposing 7,000 AI app instances to file-write attacks.
Path traversal flaw in AI dev platform Langflow exploited in attacks
Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in the AI development platform Langflow, to write arbitrary files on exposed servers.
Part of the PlainSec briefing for 2026-06-12