Vulnerabilities
Report: CVE-2026-5027 - Langflow - Path Traversal Arbitrary File Write via upload_user_file - Complete Guide
CVE ID :CVE-2026-5027 Published : March 27, 2026, 3:17 p.m. | 29 minutes ago Description :The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../'). Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...