CVE-2026-5027Active Exploitation(langflow / langflow)

CRITICALCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 25 mentions and remains active

Immediate actions

  • Patch langflow langflow systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Active exploitation appears in 58 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 82 mentions across 23 observed days

What's happening

  • Active exploitation reported across 58 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 13 signals
  • Patch or workaround mentioned in 21 signals
  • Technical details provided in 66 signals
  • Disclosure: 13 classified signals
  • General: 4 classified signals
  • Peaked 16d ago at 25 mentions (2026-06-11); latest day: 1
  • 82 total mentions across 23 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline82 mentions / 23d
06131925Mentions · 2026-03-27: 2Mentions · 2026-03-28: 1Mentions · 2026-04-02: 1Mentions · 2026-04-03: 3Mentions · 2026-04-12: 1Mentions · 2026-06-10: 23Mentions · 2026-06-11: 25Mentions · 2026-06-12: 6Mentions · 2026-06-13: 2Mentions · 2026-06-14: 2Mentions · 2026-06-15: 2Mentions · 2026-06-18: 1Mentions · 2026-06-19: 1Mentions · 2026-06-20: 2Mentions · 2026-06-21: 1Mentions · 2026-06-22: 1Mentions · 2026-07-08: 1Mentions · 2026-07-09: 1Mentions · 2026-07-14: 2Mentions · 2026-07-15: 1Mentions · 2026-07-16: 1Mentions · 2026-10-01: 1Mentions · 2026-10-02: 1PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-04-03: 2PoC Mentioned / Linked · 2026-06-10: 3PoC Mentioned / Linked · 2026-06-11: 3PoC Mentioned / Linked · 2026-06-12: 2PoC Mentioned / Linked · 2026-06-14: 1PoC Mentioned / Linked · 2026-06-20: 1Exploit Tool / Code · 2026-04-02: 1Exploit Tool / Code · 2026-04-03: 2Active Exploitation · 2026-06-10: 22Active Exploitation · 2026-06-11: 18Active Exploitation · 2026-06-12: 4Active Exploitation · 2026-06-13: 1Active Exploitation · 2026-06-14: 2Active Exploitation · 2026-06-15: 2Active Exploitation · 2026-06-18: 1Active Exploitation · 2026-06-19: 1Active Exploitation · 2026-06-20: 1Active Exploitation · 2026-06-21: 1Active Exploitation · 2026-06-22: 1Active Exploitation · 2026-07-08: 1Active Exploitation · 2026-07-09: 1Active Exploitation · 2026-07-14: 1Active Exploitation · 2026-07-15: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-06-10: 5Patch / Workaround · 2026-06-11: 4Patch / Workaround · 2026-06-12: 4Patch / Workaround · 2026-06-13: 1Patch / Workaround · 2026-06-14: 1Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-19: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-14: 1Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 3Technical Details · 2026-04-12: 1Technical Details · 2026-06-10: 20Technical Details · 2026-06-11: 19Technical Details · 2026-06-12: 6Technical Details · 2026-06-13: 1Technical Details · 2026-06-14: 2Technical Details · 2026-06-15: 1Technical Details · 2026-06-18: 1Technical Details · 2026-06-19: 1Technical Details · 2026-06-20: 1Technical Details · 2026-06-22: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-14: 2Technical Details · 2026-07-15: 103-2704-0204-1206-1106-1306-1506-1906-2107-0807-1407-1610-02
Signal classification6 categories
Active Exploitation
5670.0%
Disclosure
1316.3%
General
45.0%
PoC
33.8%
Patch
33.8%
Exploit
11.3%
Referenced assets59 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-272
Disclosure2
2026-03-281
Disclosure1
2026-04-021
PoC1
2026-04-033
Disclosure1PoC2
2026-04-121
Disclosure1
2026-06-1023
Active Exploitation21Disclosure1Patch1
2026-06-1125
Active Exploitation18Disclosure3Exploit1General3
2026-06-126
Active Exploitation4Disclosure2
2026-06-132
Active Exploitation1Patch1
2026-06-142
Active Exploitation2
2026-06-152
Active Exploitation2
2026-06-181
Active Exploitation1
2026-06-191
Active Exploitation1
2026-06-202
Active Exploitation1Disclosure1
2026-06-211
Active Exploitation1
2026-06-221
Active Exploitation1
2026-07-081
Active Exploitation1
2026-07-091
Patch1
2026-07-142
Active Exploitation1Disclosure1
2026-07-151
Active Exploitation1
2026-07-161
General1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CVE-2026-5027: Critical Path Traversal / Arbitrary File Write vulnerability in Langflow’s `POST /api/v2/files` endpoint. CVSS 8.8 https://t.co/oAoIDZuwW7

    Post summary

    The tweet announces CVE-2026-5027, a path traversal and arbitrary file write flaw in Langflow’s `/api/v2/files` endpoint, with a CVSS score of 8.8. No PoC, exploit code, patch, or active exploitation details are included.

    23401827620.4K
    221.0K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ CVE-2026-5027: Langflow Path Traversal to Remote Code Execution PoC CVSS: 8.8 GitHub: https://github.com/yahiahamza/CVE-2026-5027 https://t.co/fURDfaL6Rv

    Post summary

    The post announces CVE‑2026‑5027, a path traversal vulnerability with CVSS 8.8, and provides a PoC via GitHub, but makes no claim of active exploitation or available patches.

    23721717020.5K
    218.4K followersView on X
  • NullSecurityX@NullSecurityX
    Disclosure

    CVE-2026-5027 (CVSS 8.8)⚠️ Critical Path Traversal / Arbitrary File Write vulnerability in Langflow’s `POST /api/v2/files` endpoint. #BugBounty #CyberSecurity https://t.co/fET07mSAnC

    Post summary

    The tweet announces a CVSS 8.8 Path Traversal/Arbitrary File Write vulnerability in Langflow’s API endpoint, providing key technical details but no proof of concept, exploit, patch, or evidence of active exploitation.

    32311718210.5K
    11.8K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ An unpatched Langflow flaw is now being exploited in the wild. The catch: default auto-login can let attackers reach the vulnerable endpoint without credentials, then run their own code. About 7,000 Langflow instances are exposed online. Read: https://thehackernews.com/2026/06/unpatched-langflow-flaw-cve-2026-5027.html

    Post summary

    Langflow’s unpatched flaw (CVE-2026-5027) is actively exploited via a default auto‑login vulnerability that lets attackers run code on thousands of exposed instances.

    11303847.1K
    2.0M followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🤖🚨 AI FOUND THE VULNERABILITY. ATTACKERS WEAPONIZED IT FOUR DAYS LATER. Google Threat Intelligence Group has published new data showing how quickly AI-discovered vulnerabilities are crossing into real-world attacks. One case stands out: CVE-2026-1731 The unauthenticated OS command-injection vulnerability affecting BeyondTrust Privileged Remote Access and Remote Support was discovered AUTONOMOUSLY by the Hacktron AI research agent. Then attackers arrived. GTIG observed: * First threat cluster exploiting it within FOUR DAYS of disclosure * Five additional threat clusters within SEVEN DAYS * Privilege escalation * Data exfiltration * SNOWLIGHT deployment * SPARKRAT deployment * Cryptominer deployment But Google's broader dataset may be even more important. Exactly 50% of vulnerabilities identified as AI-discovered resulted in REMOTE CODE EXECUTION. Across the broader vulnerability ecosystem? 26%. AI is also becoming a target itself. GTIG tracked 2,076 AI-related CVEs from January 2025 through August 2026. More than 1,500 appeared in just the first eight months of 2026. The largest attack surface: * 782 vulnerabilities in AI orchestration/agent frameworks * 230 in AI web apps * 212 in inference/serving infrastructure * 106 model-security advisories * 99 affecting ML frameworks/hubs * 97 involving frontier-model tooling Orchestration middleware alone now represents roughly HALF of AI-related vulnerabilities and saw a 347% surge in disclosures during 2026. Attackers are already exploiting AI middleware in the wild. Google highlights: * LiteLLM CVE-2026-42271 — command injection → host takeover/API credential theft * Langflow CVE-2026-5027 — arbitrary file write * Langflow CVE-2025-3248 — unauthenticated Python code injection → RCE ⚠️ Analyst Note: AI is beginning to compress BOTH sides of the vulnerability lifecycle. Defensive agents can autonomously discover difficult, high-impact bugs. Attackers can then weaponize those disclosures almost immediately. Four days from AI discovery disclosure to observed exploitation is a warning about where vulnerability management is heading: PATCH WINDOWS ARE SHRINKING. https://cloud.google.com/blog/topics/threat-intelligence/vulnerability-discovery-and-exploitation-trends-in-the-ai-era #AISecurity #VulnerabilityResearch #RCE #BeyondTrust #LiteLLM #Langflow #ThreatIntel #DDW

    12029106.9K
    207.5K followersView on X
  • ボス@サイバーセキュリティの専門家@boss_sec_labo
    Active Exploitation

    AIを使う側が、狙われる番に回った。 開発を支えるAIツールと暗号・監視の土台が同じ日に穴を突かれ、足元の国内では教育と子どもの情報が漏れた。 ・OpenSSLにCVE-2026-45447、解放後使用の高危険度脆弱性をClaudeが発見 ・AIコーディング支援を騙すAgentjacking、Sentry偽エラーで任意コード実行 ・Langflow CVE-2026-5027、Path Traversalで任意ファイル書き込みを悪用 ・Splunk Enterprise CVE-2026-20253、CVSS 9.8の未認証RCE ・Oracle PeopleSoft CVE-2026-35273、CISAがKEV追加で悪用確認 ・The Gentlemenランサム、AI支援RaaSで478被害を主張 ・学習塾CKCネットワーク・学参がランサム被害、個人情報漏えいの恐れ ・日本大学文理学部サイトが改ざん、カジノサイトへ誘導 ・写真販売「はいチーズ!フォト」不正アクセス、子どもの情報漏えいの可能性 守る道具まで乗っ取られる時代だ。君の現場で今日最初に当てるパッチは決まったか? "後でいい"は、攻撃者への贈り物だ。

    Post summary

    The post lists multiple recent CVEs with technical details, noting that CVE‑2026‑35273 has been confirmed exploited by CISA, while offering no PoC, exploit code, or patch information.

    03027103.8K
    1.5K followersView on X
  • blueblue@piedpiper1616
    PoC

    GitHub - EQSTLab/CVE-2026-5027: Langflow, Remote Code Execution (RCE) via Cron Job Injection through Path Traversal (CVE-2026-5027) · GitHub - https://github.com/EQSTLab/CVE-2026-5027

    Post summary

    The GitHub repository provides a PoC for a RCE vulnerability in Langflow, but no evidence of active exploitation or available patches is discussed.

    030961.4K
    5.5K followersView on X
  • White Knight Labs@WKL_cyber
    Active Exploitation

    CISA is ordering feds to patch CVE-2026-5027 in Langflow — attackers are actively using this path traversal flaw to write arbitrary files on AI agent servers. Your LLM dev platform is now part of the threat surface. Is yours tested? https://bit.ly/3Rbbh45 https://t.co/dRsMm2JBk6

    Post summary

    CISA has mandated patches for CVE‑2026‑5027 after confirming attackers are actively exploiting a path traversal flaw in Langflow, which allows arbitrary file writes on AI agent servers.

    01082700
    899 followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE https://thehackernews.com/2026/06/unpatched-langflow-flaw-cve-2026-5027.html

    Post summary

    An unpatched CVE‑2026-5027 in Langflow has been actively exploited to gain unauthenticated remote code execution, with no patch or remediation mentioned.

    010621.2K
    158.9K followersView on X
  • Foundry Daily@FoundryDaily
    Active Exploitation

    🚨 Critical security alert: Attackers are actively exploiting a high-severity path traversal flaw (CVE-2026-5027) in the AI development platform Langflow. Users must patch immediately to prevent arbitrary file writes on exposed servers. https://t.co/1apfupD1bv

    Post summary

    The tweet announces that CVE-2026-5027, a path traversal flaw in Langflow, is being actively exploited and urges users to patch immediately to prevent arbitrary file writes.

    1004035
    18 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-5027 - high 🚨 Langflow <= 1.8.4 - Path Traversal to RCE via File Upload > The application contains a path traversal vulnerability caused by unsanitized 'filena... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-5027 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE‑2026‑5027 for Langflow, outlining a path traversal flaw that can lead to RCE via file upload, and provides a link presumably containing PoC details.

    00022132
    952 followersView on X
  • Anavem.com@Anavem_
    Active Exploitation

    Langflow CVE-2026-5027 Exploited for Remote Code Execution #cve20265027 #langflow #remotecodeexecution https://www.anavem.com/en/news/cybersecurity/langflow-cve-2026-5027-exploited-for-remote-code-execution

    Post summary

    The post reports that CVE-2026-5027 in Langflow has been actively exploited for remote code execution, but no details on patches or technical specifics are provided.

    01020303
    165 followersView on X
  • Orca Security@orcasec
    Active Exploitation

    🚨 CRITICAL: Langflow CVE-2026-5027 (CVSS 8.8) Unauthenticated attackers can achieve full RCE with a single request, no credentials needed. ~7,000 instances are publicly exposed and active exploitation is confirmed. Patch to 1.10.0 now. Full breakdown 👇 https://orca.security/resources/blog/cve-2026-5027-langflow-path-traversal-rce/?utm_source=twitter&utm_medium=organic+social&utm_campaign=orca+blog https://t.co/p0b71TVFFm

    Post summary

    The tweet announces a critical CVE-2026-5027 that is actively exploited, offers a patch to version 1.10.0, and links to a detailed breakdown likely containing PoC details.

    0002089
    4.8K followersView on X
  • 泉水亮介 │ 大学でVibe Codingを教えてます。@rsensui
    Active Exploitation

    📰 Tech News — 今朝のAIホットトピック(06/11)🧵 🔒 AI開発基盤Langflowの未修正脆弱性 CVE-2026-5027 が実環境で悪用 🤖 Gemini 3.5 Pro が6月中旬GA間近 🚀 Claude Fable 5 が全環境で一般提供開始(Mythos 5 は限定)— 使い方の作法も更新 📊 Fable 5 の実力検証 🛠️ Fable 5 で開発の作法が変わる ⚠️ Fable 5 は性能圧倒的だが Anthropic の方針が炎上 📅 Anthropic「Code with Claude」ツアー最終地として東京開催を告知

    Post summary

    CVE‑2026‑5027, an unpatched vulnerability in the Langflow AI development platform, has been reported as actively exploited in production environments, with no PoC, patch, or technical details provided.

    10010545
    2.1K followersView on X
  • yousukezan@yousukezan
    Active Exploitation

    AIアプリ開発向けオープンソースプラットフォーム「Langflow」の未修正脆弱性CVE-2026-5027が実際に悪用されていることが確認された。VulnCheckによると、この脆弱性はパストラバーサルの問題で、攻撃者が任意の場所へファイルを書き込める可能性がある。 この脆弱性はTenableが発見したもので、POST /api/v2/filesエンドポイントがアップロード時のfilenameパラメータを適切に検証していないことに起因する。攻撃者は「../」を含むパストラバーサル文字列を利用し、ファイルシステム上の任意の場所へファイルを書き込むことができる。 VulnCheckのCaitlin Condon氏によると、この問題はリモートコード実行につながる可能性がある。また、Langflowではデフォルト設定で認証不要の自動ログイン機能が有効になっているため、攻撃者は認証情報なしで脆弱なエンドポイントへ到達でき、単一のリクエストで有効なセッショントークンを取得できるという。 現在確認されている攻撃では、対象システムへテスト用ファイルを書き込む活動が行われている。Censysのデータによると、インターネット上には約7,000のLangflowインスタンスが公開されており、その多くは北米に存在する。 Langflowでは今年に入り、CVE-2026-0770、CVE-2026-33017、CVE-2026-21445、CVE-2025-34291など複数の脆弱性が攻撃対象となっている。記事によると、CVE-2025-34291はイラン系の国家支援グループ「MuddyWater」による悪用も確認されている。 https://thehackernews.com/2026/06/unpatched-langflow-flaw-cve-2026-5027.html

    Post summary

    The article confirms that the unpatched CVE-2026-5027 in Langflow is being actively exploited via path traversal, enabling file writes and possible remote code execution without authentication, with no patch or workaround mentioned.

    000201.1K
    14.6K followersView on X
  • Davin Jackson@Djax_Alpha
    General

    CVE-2025-3248 and CVE-2026-5027: Langflow RCE Vulnerabilities Explained https://cybersec.picussecurity.com/s/cve-2025-3248-and-cve-2026-5027-langflow-rce-vulnerabilities-explained-28561/1

    Post summary

    The article cites two RCE vulnerabilities (CVE‑2025‑3248, CVE‑2026‑5027) in Langflow but does not provide PoC details, exploit code, or other substantive information within the provided text.

    00010175
    9.1K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    CISA KEV 警告 26/07/07:Langflow の脆弱性 CVE-2026-55255 を KEV に登録 https://iototsecnews.jp/2026/07/08/cisa-orders-feds-to-prioritize-patching-langflow-auth-bypass-flaw/ AI 開発で人気の Langflow に存在する、深刻な脆弱性が CISA KEV に登録されました。認証済みの攻撃者が、悪意のリクエストを特定のエンドポイントへ送信することで、適切な検証が行われずに他者のデータへのアクセスが可能になってしまいます。また、過去に悪用された CVE-2025-3248 のような認証欠如や、CVE-2026-33017 のコードインジェクション、CVE-2026-5027 のパストラバーサルといった複数のバグも、攻撃者に狙われています。 #CVE202655255 #Exploit #KEV #Langflow #Vulnerability

    Post summary

    CISA has listed CVE‑2026‑55255 in its KEV database, confirming real‑world exploitation; no PoC, exploit code, patch, or false‑positive claim are mentioned.

    01000135
    502 followersView on X
  • Ousmane Barry, PhD@drbarryofficial
    Active Exploitation

    1. Langflow's CVE-2026-5027 was exploited in the wild. Your AI dev tooling is now an internet-facing production app with credentials. Inventory it.

    Post summary

    The text reports that Langflow’s CVE-2026-5027 has been actively exploited in the wild, indicating an immediate security risk.

    1000035
    5 followersView on X
  • Connex@Connex01
    Disclosure

    3/ 1. Langflow Unauthenticated RCE (CVE-2026-5027) • The Bug: A path traversal flaw in the POST /api/v2/files endpoint. • The Catch: Langflow ships with "auto-login" enabled by default.

    Post summary

    Langflow has an unauthenticated RCE (CVE-2026-5027) due to a path traversal flaw in the POST /api/v2/files endpoint, exacerbated by auto-login being enabled by default. No PoC, exploit code, active exploitation claims, or patch information is provided.

    1000054
    102 followersView on X
  • Ousmane Barry, PhD@drbarryofficial
    Active Exploitation

    Your AI dev stack is the new attack surface, and a live exploit this week proved it. CVE-2026-5027 in Langflow. A thread on why your agent tooling is now production risk.

    Post summary

    A live exploit for CVE-2026-5027 in Langflow demonstrates that this CVE is being actively exploited, exposing AI development tooling as a new attack surface.

    1000014
    5 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more