Unrated severityNVD Advisory· Published Mar 27, 2026· Updated Mar 27, 2026
Langflow - Path Traversal Arbitrary File Write via upload_user_file
CVE-2026-5027
Description
The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').
Affected products
1- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.