{"id":"CVE-2026-5027","title":"The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').","summary":"The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-22"],"vendor":"langflow","product":"langflow","affected":["langflow < 1.9.0"],"patched":["langflow 1.9.0"],"published":"2026-03-27","updated":"2026-08-18","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-5027","references":[{"url":"https://www.tenable.com/security/research/tra-2026-26","label":"vulnreport@tenable.com"}],"tags":["nvd","exploit-available"],"epss":0.36141,"epssPercentile":0.98451,"ingestedAt":"2026-08-18T18:21:28.429Z","exploitAvailable":true,"exploits":{"exploitdb":true,"github":7,"githubRepos":["https://github.com/yahiahamza/CVE-2026-5027","https://github.com/min8282/CVE-2026-5027","https://github.com/EQSTLab/CVE-2026-5027"],"nuclei":["CVE-2026-5027"],"checkedAt":"2026-09-21T15:29:20.095Z"},"slug":"CVE-2026-5027","body":"## Overview\n\nThe 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').\n\n## Affected\n\n- `langflow < 1.9.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `langflow 1.9.0`","depth":"midnight","depthScore":68,"depthScoreParts":{"impact":48.4,"likelihood":7.2,"exploitation":12,"ransomware":0},"changes":[{"seq":211,"id":"CVE-2026-5027","ts":1788296375781,"field":"exploit_available","old":"false","new":"true"}]}