Vulnerability  ·  2026-10-03

Langflow knowledge-base create: directory traversal permits arbitrary file write outside storage boundary (CVE-2026-51888)

VulnerabilityMedium impactGlobalCVE-2026-51888
NVD published CVE-2026-51888 on 2026-10-01 (unrated): directory traversal in the Langflow knowledge-base creation endpoint enables arbitrary file write outside the workspace/storage boundary (RAG data-ingestion path).
Langflow is used to build RAG pipelines; a traversal in the KB-ingest path is an arbitrary-file-write on the LLM application host — lower priority than the validated code-exec CVE but worth cataloguing.
A live HTTP POST creating a knowledge base with a traversal path writes files outside the intended storage boundary on the Langflow server.
Langflow 1.8.4
Apply upstream fix once available; restrict authenticated access to knowledge-base creation until patched.
NVD CVE-2026-51888
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →