PT-2026-28741 · Unknown · Api/V2/Files

CVE-2026-5027

·

Published

2026-03-27

·

Updated

2026-07-16

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Langflow versions prior to 1.9.0
Description Langflow contains a path traversal flaw where the 'POST /api/v2/files' endpoint fails to sanitize the filename parameter within multipart form data. This allows an attacker to use path traversal sequences (../) to write files to arbitrary locations on the filesystem, which can lead to remote code execution depending on writable paths and permissions. The risk is amplified by a default configuration that enables unauthenticated auto-login, allowing attackers to obtain a valid session token and access the vulnerable endpoint without credentials. Approximately 7,000 exposed instances worldwide have been identified, and the issue is under active exploitation by the threat actor MuddyWater.
Recommendations Upgrade to Langflow version 1.9.0. Disable the default auto-login feature to prevent unauthenticated access to the system. Restrict access to the 'POST /api/v2/files' endpoint to minimize the risk of exploitation.

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5027

Affected Products

Api/V2/Files