logo

Langflow Alert: Path Traversal Flaw in Knowledge Bases API Risks Total Data Wipeout

ID: ad9cd284-35ba-592c-a3e7-14b56c032add

STIX ID: report--ad9cd284-35ba-592c-a3e7-14b56c032add

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Ddos

...
...

Langflow patched CVE-2026-42048, a critical (CVSS 9.6) vulnerability in its bulk knowledge-base deletion handler that allowed authenticated users to perform path-traversal via the kb_names parameter and trigger shutil.rmtree() on arbitrary directories. The bug bypassed standard sanitization, risking cross-user data deletion and service disruption; developers fixed it by resolving and validating paths and ensuring deletions remain inside the user's directory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.