Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE
ID: 55fdbd68-f164-5aef-86f7-0e9c24b4e833
STIX ID: report--55fdbd68-f164-5aef-86f7-0e9c24b4e833
Feed Name: The Hacker News
A high-severity (CVSS 8.8) path traversal vulnerability (CVE-2026-5027) in the open-source Langflow low-code AI platform is being actively exploited to write files to arbitrary filesystem locations and may enable remote code execution; the POST /api/v2/files endpoint fails to sanitize the multipart 'filename' parameter and Langflow's default unauthenticated auto-login makes exploitation trivial. Tenable and VulnCheck reported the flaw after attempted coordinated disclosure, Censys data shows roughly 7,000 exposed Langflow instances (many in North America), exploitation activity has been observed writing test files, and this activity follows prior attacks against other Langflow CVEs including one linked to the MuddyWater actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
