← Back to browse · API

CVE-2026-5027

Severity
HIGH
CVSS
8.8
EPSS
0.31405
Risk score
46.19
CISA KEV
No
PoC
Yes
Published
2026-03-27
Modified
2026-03-27
First seen
2026-08-07
Aliases
EUVD-2026-16668
Products
langflow-ai:langflow 0
Sources
euvd EUVD-2026-16668
packetstorm e1b15243aca2ad53b47ce4cf|CVE-2026-5027

Description

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

References