Vulnerability threat dossier

CVE-2026-5027

langflowlangflow

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

VTP deterministic threat28.7of 100 · CVSS excluded

VTP analyst assessment

Langflow authenticated arbitrary file write

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityMEDIUM
AI confidence72%
Public exploitation · VTP factREPORTED

Assessment

Langflow's POST /api/v2/files endpoint permits path traversal through the multipart filename parameter, allowing a low-privileged remote attacker to write files outside the intended location. A primary assertion reports a public exploit template, but its reliability is unestablished. The exploitation-reporting evidence is weak for this CVE because the supplied press summaries discuss CVE-2026-0768 rather than CVE-2026-5027.

Why it matters

  • Arbitrary filesystem writes can compromise confidentiality, integrity, and availability, reflected in the supplied CVSS 3.1 score of 8.8.
  • Network reachability, low privileges, and no required user interaction make exposed vulnerable endpoints practically relevant.
  • EPSS 0.36141 is elevated predictive context but does not prove exploitation.

Evidence

4 record references and 4 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The bundle labels exploitation as reported, but the associated source summaries identify a different Langflow CVE; exploitation of CVE-2026-5027 is therefore not corroborated by the supplied text.

The affected version boundaries and exploit template's functional reliability are not supplied.

The required privilege level is stated by the CVSS vector but the exact application role or permission is unspecified.

No first-party sensor telemetry is configured, so VTP observation is unknown.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Confirm vulnerable Langflow versions and access controls on POST /api/v2/files.

AI baseline history (3)
  1. BASELINE ASSESSED
    Langflow authenticated arbitrary file writegpt-5.6-sol · high
  2. BASELINE ASSESSED
    Authenticated arbitrary file write with disputed exploitation linkagegpt-5.6-sol · high
  3. BASELINE ASSESSED
    Authenticated arbitrary file write via path traversalgpt-5.6-sol · high
Technical severityHIGHCVSS 8.8 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.3698th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    A proof of concept is reported; functional reliability is not established.

  2. 02

    EPSS is 0.36; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
03

Claim provenance

Evidence and source independence

5publications detected
5underlying evidence chains

0 primary sources · 0 dependent secondary reports · 4 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:8f7454a1232a1630e59d9a8592cd02a1dbe579cfc6dabaa971ecb157233852afACTIVE
Evidence
Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:EXPLOIT_DB:760758183918a185b40b783308359bbeef86362bACTIVE
Evidence
04

Event history

Threat timeline

  1. 12:0701 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    SecurityWeek supplied a deterministically extracted signal; review the linked evidence before escalation.

  2. 02:3101 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    OffSec Exploit Database published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  3. 19:1823 Jun
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-5027.

05

Original publications

Source record

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...]

CVE-2026-0768CVE-2026-0770CVE-2026-33017CVE-2026-5027CVE-2026-55255CVE-2026-9198
Separate evidence group
Original

Hackers Start Exploiting Critical Langflow Vulnerability

Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely. The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek .

CVE-2025-3248CVE-2026-0768CVE-2026-0769CVE-2026-5027
Separate evidence group
Original

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka

CVE-2025-3248CVE-2026-0768CVE-2026-0769CVE-2026-5027CVE-2026-66066
Separate evidence group
Original

Exploit tooling coverage changed for 8 CVEs

OffSec Exploit Database recorded exploit-tooling coverage changes for 8 CVEs in this pinned revision. 8 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2025-60689CVE-2026-5027CVE-2026-51133CVE-2026-51134CVE-2026-54644CVE-2026-54645CVE-2026-54646CVE-2026-54647
Separate evidence group
Original

Nuclei Templates v10.4.5 - Release Notes

New Templates Added: 86 | CVEs Added: 64 | First-time contributions: 22 🔥 Release Highlights 🔥 [ CVE-2026-50751 ] Check Point IKEv1 Remote-Access VPN - Certificate Auth Bypass ( @watchtowr , @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-49777 ] WordPress Product Slider Pro for WooCommerce < 3.5.4 - Supply Chain Backdoor RCE ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-48907 ] Joomla! JCE extension < 2.9.99.5 Unauth RCE ( @ywh-jfellus ) [critical] (vKEV) 🔥 [ CVE-2026-48710 ] Starlette - Improper Validation of Unsafe Equivalence in Input ( @ritikchaddha ) [critical] 🔥 [ CVE-2026-44551 ] Open WebUI 'LDAP Empty Password' - Auth Bypass ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-44338 ] PraisonAI - Auth Bypass ( @jnoza ) [high] (vKEV) 🔥 [ CVE-2026-44262 ] Scramble Laravel - Remote Code Execution ( @joshuavanderpoll ) [critical] 🔥 [ CVE-2026-42647 ] JoomSport <= 5.7.7 - SQL Injection ( @theamanrawat ) [critical] (vKEV) 🔥 [ CVE-2026-42589 ] Gotenberg - Command Injection ( @fineman999 ) [critical] (vKEV) 🔥 [ CVE-2026-42271 ] LiteLLM - Command Injection ( @ritikchaddha ) [critical] (vKEV) 🔥 [ CVE-2026-42208 ] LiteLLM - SQL Injection ( @HAERIN-L ) [critical] (vKEV) 🔥 [ CVE-2026-35273 ] Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCE ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-34910 ] UniFi OS Server - Command Injection (@Kazgangap) [critical] (vKEV) 🔥 [ CVE-2026-31431 ] Copy Fail - Linux Kernel Local Privilege Escalation via AF_ALG ( @ritikchaddha ) [high] (vKEV) 🔥 [CVE-2026-29059] Windmill/Nextcloud Flow < 1.603.3 - Unauth Path Traversal (@0x_Akoko) [critical] 🔥 [ CVE-2026-27760 ] OpenCATS - Command Injection ( @theamanrawat ) [high] (vKEV) 🔥 [ CVE-2026-26190 ] Milvus - Unauth Metrics API Access ( @WRG-11 ) [critical] 🔥 [ CVE-2026-22557 ] UniFi Network Application - Path Traversal ( @Aryu-RU ) [critical] 🔥 [ CVE-2026-20253 ] Splunk Enterprise & Cloud Platform - Unrestricted File Upload ( @watchtowrlabs , @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-10795 ] UpdraftPlus WP Backup & Migration Plugin - Auth Bypass ( @theamanrawat , @s4e-io ) [high] (vKEV) 🔥 [ CVE-2026-10520 ] Ivanti Sentry - OS Command Injection ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-5073 ] WordPress ARMember Premium <= 7.3.1 - Unauth SQL Injection ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-5027 ] Langflow <= 1.8.4 - Path Traversal to RCE via File Upload ( @pussycat0x ) [high] (vKEV) 🔥 [ CVE-2026-4480 ] Samba Printing Subsystem - Remote Code Execution ( @projectdiscovery ) [critical] 🔥 [ CVE-2026-3300 ] Everest Forms Pro <= 1.9.12 - Unauth RCE via Calculation Formula Injection ( @dhiyaneshdk ) [critical] (vKEV) 🔥 [ CVE-2026-3018 ] WordPress Newsletters <= 4.13 - Unauth SQL Injection ( @pussycat0x ) [high] (vKEV) 🔥 [ CVE-2026-0257 ] Palo Alto Networks PAN-OS - Auth Bypass ( @dhiyaneshdk , @sfewer-r7 ) [critical] (vKEV) 🔥 [CVE-2025-49001] DataEase < 2.10.10 - JWT Auth Bypass ( @YunSeoJo , @Aryu-RU ) [critical] 🔥 [ CVE-2025-13773 ] WordPress Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Remote Code Execution ( @PikaJuna-ops ) [critical] (vKEV) 🔥 What's Changed Bug Fixes Fixed invalid double-port URL construction in hpe-autopass-panel where {{Hostname}} was used instead of {{Host}}, producing malformed URLs like hostname:6274:5814/autopass (PR #16316 , Issue #16315 ). Fixed incorrect CVE assignment in a contributed template, correcting the CVE ID to match the actual vulnerability (PR #16397 , Issue #16388 ). Fixed username variable syntax error in CVE-2026-44551 .yaml causing broken authentication attempts (PR #16341 ). Corrected broken reference links in CVE-2020-27361 .yaml (PR #16403 ). Fixed typo in tags field of wp-jetpack-ssrf.yaml (PR #16347 ). Moved CVE-2020-14644 .yaml to the correct folder in the repository structure (PR #16432 ). False Negatives Fixed a broken regex in the waf-detect BIG-IP ASM matcher that used start-of-response anchors (\A, ^) against a blob beginnin

CVE-2018-11776CVE-2020-14644CVE-2020-27361CVE-2020-36884CVE-2020-5776CVE-2021-3239CVE-2022-44727CVE-2023-5652CVE-2024-12008CVE-2024-6569CVE-2025-13339CVE-2025-13773CVE-2025-25296CVE-2025-47783CVE-2025-49001CVE-2025-51586CVE-2025-61224CVE-2026-0257CVE-2026-10520CVE-2026-10580CVE-2026-10795CVE-2026-20253CVE-2026-22557CVE-2026-25527CVE-2026-25555CVE-2026-26190CVE-2026-2652CVE-2026-27760CVE-2026-27771CVE-2026-27826CVE-2026-27833CVE-2026-29059CVE-2026-3018CVE-2026-31431CVE-2026-3300CVE-2026-33476CVE-2026-34910CVE-2026-35273CVE-2026-40151CVE-2026-41492CVE-2026-42208CVE-2026-42271CVE-2026-42589CVE-2026-42647CVE-2026-44262CVE-2026-44338CVE-2026-44551CVE-2026-4480CVE-2026-45298CVE-2026-45397CVE-2026-46364CVE-2026-47670CVE-2026-47717CVE-2026-48710CVE-2026-48907CVE-2026-49777CVE-2026-50230CVE-2026-5027CVE-2026-5073CVE-2026-50751CVE-2026-53787CVE-2026-54066CVE-2026-54069CVE-2026-54157CVE-2026-54236CVE-2026-55592CVE-2026-7798CVE-2026-8054CVE-2026-8839CVE-2026-9290
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score28.7vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction7.23 / 20
Exploit availability7.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-22
CPE records
1
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.