What happened
NVD published CVE-2026-51888 on 2026-10-01 (unrated): directory traversal in the Langflow knowledge-base creation endpoint enables arbitrary file write outside the workspace/storage boundary (RAG data-ingestion path).
Why it matters
Langflow is used to build RAG pipelines; a traversal in the KB-ingest path is an arbitrary-file-write on the LLM application host — lower priority than the validated code-exec CVE but worth cataloguing.
Attack vector
A live HTTP POST creating a knowledge base with a traversal path writes files outside the intended storage boundary on the Langflow server.
Affected systems
Langflow 1.8.4
Mitigation
Apply upstream fix once available; restrict authenticated access to knowledge-base creation until patched.