---
id: CVE-2026-51888
title: 'langflow-ai langflow v1.8.4 is affected by: Directory Traversal'
summary: >-
  langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact
  is: Arbitrary file write outside the intended workspace or storage boundary..
  The component is:
  src/backend/base/langflow/api/v1/knowledge_bases.py:knowledge_bas…
severity: none
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T22:17:03.527'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-51888'
references:
  - url: 'https://gist.github.com/Ro1ME/c85f513d1fd702c686cffe061cbf8ef5'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T23:03:32.776Z'
---

## Overview

langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundary.. The component is: src/backend/base/langflow/api/v1/knowledge_bases.py:knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing upload or HTTP route handler forwards an attacker-controlled path or filename into host file creation without any visible boundary enforcement. ¶¶ A weakness has been identified in langflow-ai langflow up to 1.8.4. langflow contains an absolute path traversal vulnerability in knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base (src/backend/base/langflow/api/v1/knowledge_bases.py:51). An attacker can write or overwrite files outside the intended working directory by providing absolute paths in the knowledge base creation endpoint.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
