Vulnerability  ·  2026-06-19

Langflow CVE-2026-5027 Path Traversal to Unauthenticated RCE via File Upload

VulnerabilityHigh impactGlobalCVE-2026-5027
Langflow's file-upload endpoint fails to sanitize the 'filename' parameter, allowing attackers to write files to arbitrary filesystem locations. Default auto-login feature eliminates authentication requirement. Arbitrary file write can be escalated to RCE via configuration/startup file overwrites.
Langflow is a low-code platform for building AI agents and RAG pipelines and sits at the core of many AI orchestration deployments. RCE as unauthenticated user exposes all connected API keys, vector DB credentials, and model endpoints. Active exploitation confirmed by VulnCheck on 2026-06-09; third Langflow RCE this year.
POST /api/v2/files endpoint with path traversal sequences (../) in unsanitized 'filename' parameter; combined with auto-login default behavior allows unauthenticated RCE via cron/startup file injection
Langflow ≤ 1.8.4 (fixed in 1.9.0, released 2026-04-15)
Upgrade to Langflow 1.9.0 or later; disable auto-login; restrict network access via VPN/reverse proxy; disable write permissions where possible
Sources
CSO Online - Langflow RCE under active attackThe Hacker News - Unpatched Langflow Flaw CVE-2026-5027Tenable Security Advisory TRA-2026-26Linux SecurityThe Hacker News - Langflow RCE ExploitationPalo Alto Networks Unit 42 - Pickle in the Middle – Hijacking Vertex AI Model Uploads
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →