CVE-2026-42048Disclosure(langflow / langflow)

MEDIUMCVSS 9.6 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch langflow langflow systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are concatenated directly into file paths without proper sanitization or boundary validation. An authenticated attacker can exploit this flaw to delete arbitrary directories anywhere on the server's filesystem, leading to data loss and potential service disruption. This vulnerability is fixed in 1.9.0.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 7 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-06-16)
  • 8 total mentions across 7 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline8 mentions / 7d
01122Mentions · 2026-04-28: 1Mentions · 2026-04-29: 1Mentions · 2026-05-07: 1Mentions · 2026-05-10: 1Mentions · 2026-05-12: 1Mentions · 2026-05-14: 1Mentions · 2026-06-16: 2PoC Mentioned / Linked · 2026-05-14: 1Active Exploitation · 2026-06-16: 1Patch / Workaround · 2026-04-28: 1Patch / Workaround · 2026-05-07: 1Technical Details · 2026-04-28: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-12: 1Technical Details · 2026-05-14: 1Technical Details · 2026-06-16: 104-2804-2905-0705-1005-1205-1406-16
Signal classification5 categories
Disclosure
450.0%
Patch
112.5%
PoC
112.5%
Active Exploitation
112.5%
General
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-281
Patch1
2026-04-291
Disclosure1
2026-05-071
Disclosure1
2026-05-101
Disclosure1
2026-05-121
Disclosure1
2026-05-141
PoC1
2026-06-162
Active Exploitation1General1
Full discourse8 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-42048 (CVSS 9.6): Path traversal in Langflow bulk KB deletion may allow authenticated attackers to wipe arbitrary directories. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJMT0dTUEFDRS1MYW5nRmxvdyI%3D 🎯2.8K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="LOGSPACE-LangFlow" 🔖Refer: https://securityonline.info/langflow

    Post summary

    The post discloses CVE‑2026‑42048, a CVSS 9.6 path‑traversal vulnerability in Langflow that could let authenticated attackers delete arbitrary directories, and provides a FOFA link to potential exposed installations.

    0201121.6K
    14.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Langflow patches a critical 9.6 CVSS path traversal vulnerability (CVE-2026-42048). Learn how an unsafe bulk delete function put entire filesystems at risk. #Langflow #CyberSecurity #CVE202642048 #InfoSec #AISecurity #BugBounty #Python https://securityonline.info/langflow-cve-2026-42048-path-traversal-bulk-delete-analysis/ https://t.co/9aiFCYGSa5

    Post summary

    Langflow has released a patch for CVE-2026-42048, a critical 9.6 CVSS path traversal vulnerability caused by an unsafe bulk delete function that could expose entire filesystems.

    02031419
    12.5K followersView on X
  • Sysdig@sysdig
    Active Exploitation

    The Sysdig early warning network has detected the first exploitation of CVE-2026-42048, a Langflow path traversal vulnerability. This attack was conducted by an Agentic Threat Actor (ATA) via LLM. Their target was credential files on the host. Attacker: 207.241.172.229 Path: DELETE /api/v1/knowledge_bases This ATA is targeting multiple #Langflow #vulnerabilities.

    Post summary

    First exploitation of CVE‑2026‑42048 reported, with the attacker targeting credential files via a DELETE request, indicating active use of a path traversal flaw.

    12020292
    10.3K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Langflow Knowledge Bases API path traversal allows arbitrary directory deletion (CVE-2026-42048) The Knowledge Bases bulk delete endpoint (DELETE /api/v1/knowledge_bases) does not properly validate user-supplied knowledge base names before building filesystem paths. This allows authenticated attackers to use path traversal (e.g. ../) to escape the intended directory scope and delete arbitrary directories via shutil.rmtree(), resulting in cross-tenant data loss and service disruption. 👉 Affected: <= 1.8.4 | Fix: 1.9.0

    Post summary

    Critical path traversal in Langflow’s Knowledge Bases API permits authenticated users to delete arbitrary directories causing data loss; the issue is fixed in version 1.9.0.

    0002080
    237 followersView on X
  • Sysdig@sysdig
    General

    CVE: https://advisories.gitlab.com/pypi/langflow/CVE-2026-42048/

    Post summary

    A URL to a GitLab advisory for CVE-2026-42048 is provided, but no explicit details or actionable information regarding the vulnerability is included in the text.

    00010142
    10.3K followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Disclosure

    Langflow had a path traversal in its bulk-delete endpoint — any logged-in user wipes arbitrary host directories (CVE-2026-42048). Pipecat's optional Livekit serializer ran pickle.loads() on raw socket data; anyone on the wire gets RCE (GHSA-c2jg-5cp7-6wc7).

    Post summary

    The text announces two newly disclosed vulnerabilities, detailing a path traversal in Langflow’s bulk‑delete endpoint and an RCE via pickle in Pipecat, without providing PoC, patches, or evidence of active exploitation.

    1000063
    34 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼️ #Langflow: disponibile #PoC per lo sfruttamento della CVE-2026-42048 Rischio: 🔴 Tipologia 🔸 Arbitrary File Deletion 🔗 https://www.acn.gov.it/portale/w/langflow-poc-pubblico-per-lo-sfruttamento-della-cve-2026-42048 🔄 Aggiornamenti disponibili 🔄 https://t.co/YwftBAtYxq

    Post summary

    A proof of concept for the Langflow CVE-2026-42048, which allows arbitrary file deletion, has been published on a public page.

    0000068
    611 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42048 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DE… https://www.cve.org/CVERecord?id=CVE-2026-42048

    Post summary

    Langflow before version 1.9.0 has a path traversal vulnerability in its Knowledge Bases API, as documented in CVE-2026-42048.

    00000143
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more