Langflow Alert: Path Traversal Flaw in Knowledge Bases API Risks Total Data Wipeout
ID: ad9cd284-35ba-592c-a3e7-14b56c032add
STIX ID: report--ad9cd284-35ba-592c-a3e7-14b56c032add
Feed Name: securityonline.info
Threat Score
Langflow patched CVE-2026-42048, a critical (CVSS 9.6) vulnerability in its bulk knowledge-base deletion handler that allowed authenticated users to perform path-traversal via the kb_names parameter and trigger shutil.rmtree() on arbitrary directories. The bug bypassed standard sanitization, risking cross-user data deletion and service disruption; developers fixed it by resolving and validating paths and ensuring deletions remain inside the user's directory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
