NullSecurityX[verified]@NullSecurityXDisclosure
The tweet announces a CVSS 8.8 Path Traversal/Arbitrary File Write vulnerability in Langflow’s API endpoint, providing key technical details but no proof of concept, exploit, patch, or evidence of active exploitation.
ボス@サイバーセキュリティの専門家[verified]@boss_sec_laboActive Exploitation
The post lists multiple recent CVEs with technical details, noting that CVE‑2026‑35273 has been confirmed exploited by CISA, while offering no PoC, exploit code, or patch information.
White Knight Labs[verified]@WKL_cyberActive Exploitation
CISA has mandated patches for CVE‑2026‑5027 after confirming attackers are actively exploiting a path traversal flaw in Langflow, which allows arbitrary file writes on AI agent servers.
Nicolas Krassas[verified]@DinosnActive Exploitation
An unpatched CVE‑2026-5027 in Langflow has been actively exploited to gain unauthenticated remote code execution, with no patch or remediation mentioned.
Foundry Daily[verified]@FoundryDailyActive Exploitation
The tweet announces that CVE-2026-5027, a path traversal flaw in Langflow, is being actively exploited and urges users to patch immediately to prevent arbitrary file writes.
Anavem.com[verified]@Anavem_Active Exploitation
The post reports that CVE-2026-5027 in Langflow has been actively exploited for remote code execution, but no details on patches or technical specifics are provided.
泉水亮介 │ 大学でVibe Codingを教えてます。[verified]@rsensuiActive Exploitation
CVE‑2026‑5027, an unpatched vulnerability in the Langflow AI development platform, has been reported as actively exploited in production environments, with no PoC, patch, or technical details provided.
yousukezan[verified]@yousukezanActive Exploitation
The article confirms that the unpatched CVE-2026-5027 in Langflow is being actively exploited via path traversal, enabling file writes and possible remote code execution without authentication, with no patch or workaround mentioned.