FOFA[verified]@fofabotDisclosure
The post discloses CVE‑2026‑42048, a CVSS 9.6 path‑traversal vulnerability in Langflow that could let authenticated attackers delete arbitrary directories, and provides a FOFA link to potential exposed installations.
Sysdig[verified]@sysdigActive Exploitation
First exploitation of CVE‑2026‑42048 reported, with the attacker targeting credential files via a DELETE request, indicating active use of a path traversal flaw.
Upwind Security MDR[verified]@UpwindMDRDisclosure
Critical path traversal in Langflow’s Knowledge Bases API permits authenticated users to delete arbitrary directories causing data loss; the issue is fixed in version 1.9.0.
Sysdig[verified]@sysdigGeneral
A URL to a GitLab advisory for CVE-2026-42048 is provided, but no explicit details or actionable information regarding the vulnerability is included in the text.
Gray Hats@the_yellow_fallPatch
Langflow has released a patch for CVE-2026-42048, a critical 9.6 CVSS path traversal vulnerability caused by an unsafe bulk delete function that could expose entire filesystems.
Technology Interpreters, Inc.@TechTranslatorsDisclosure
The text announces two newly disclosed vulnerabilities, detailing a path traversal in Langflow’s bulk‑delete endpoint and an RCE via pickle in Pipecat, without providing PoC, patches, or evidence of active exploitation.
Hephaestvs@Vulcanux_PoC
A proof of concept for the Langflow CVE-2026-42048, which allows arbitrary file deletion, has been published on a public page.
CVE@CVEnewDisclosure
Langflow before version 1.9.0 has a path traversal vulnerability in its Knowledge Bases API, as documented in CVE-2026-42048.