A high-severity path traversal vulnerability in Langflow, designated CVE-2026-5027 (CVSS 8.8), is being actively exploited in the wild. Discovered by Tenable, the flaw resides in the ‘POST /api/v2/files’ endpoint, which fails to sanitize the ‘filename’ parameter, allowing attackers to write files to arbitrary locations using path traversal sequences. Langflow’s default unauthenticated auto-login enables attackers to obtain a valid session token with a single request, leading to remote code execution (RCE).
VulnCheck reported that exploitation attempts have been observed writing test files on victim systems. Censys data reveals approximately 7,000 publicly exposed Langflow instances, primarily in North America. This attack follows a series of exploits targeting other Langflow vulnerabilities this year, including CVE-2026-0770, CVE-2026-33017, CVE-2026-21445, and CVE-2025-34291, the latter weaponized by Iranian state-sponsored group MuddyWater. The activity underscores a growing trend of attackers targeting AI application infrastructure.
Tenable confirmed that the vulnerability was patched in Langflow version 1.9.0, released on April 15, 2026. Users are urged to update immediately.
CVEs: CVE-2026-5027, CVE-2026-0770, CVE-2026-33017, CVE-2026-21445, CVE-2025-34291, CVE-2026-11645
Attack groups: MuddyWater
Companies: Tenable, VulnCheck, Censys
Products: Langflow
Original source: thehackernews.com