Path traversal flaw in AI dev platform Langflow exploited in attacks
ID: 1f64ab0e-c81f-58e4-81d6-ac58f88f0b92
STIX ID: report--1f64ab0e-c81f-58e4-81d6-ac58f88f0b92
Feed Name: Bleeping Computer
Threat Score
Langflow is being actively exploited via CVE-2026-5027, a high-severity unauthenticated path traversal in its file upload endpoint that permits arbitrary file writes; Tenable disclosed the flaw, fixes were issued (langflow-base 0.8.3 and Langflow 1.9.0, with a recommendation to upgrade to 1.10.0), and honeypots and Censys scan data show active exploitation and many potentially exposed instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
