logo

Path traversal flaw in AI dev platform Langflow exploited in attacks

ID: 1f64ab0e-c81f-58e4-81d6-ac58f88f0b92

STIX ID: report--1f64ab0e-c81f-58e4-81d6-ac58f88f0b92

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Bill Toulas

...
...

Langflow is being actively exploited via CVE-2026-5027, a high-severity unauthenticated path traversal in its file upload endpoint that permits arbitrary file writes; Tenable disclosed the flaw, fixes were issued (langflow-base 0.8.3 and Langflow 1.9.0, with a recommendation to upgrade to 1.10.0), and honeypots and Censys scan data show active exploitation and many potentially exposed instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.