Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal Allowing Arbitrary File Write in Langflow Knowledge Base Creation Endpoint | |
| Weaknesses | CWE-22 |
Thu, 01 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundary.. The component is: src/backend/base/langflow/api/v1/knowledge_bases.py:knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing upload or HTTP route handler forwards an attacker-controlled path or filename into host file creation without any visible boundary enforcement. ¶¶ A weakness has been identified in langflow-ai langflow up to 1.8.4. langflow contains an absolute path traversal vulnerability in knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base (src/backend/base/langflow/api/v1/knowledge_bases.py:51). An attacker can write or overwrite files outside the intended working directory by providing absolute paths in the knowledge base creation endpoint. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-01T21:38:02.265Z
Reserved: 2026-06-08T00:00:00.000Z
Link: CVE-2026-51888
No data.
Status : Received
Published: 2026-10-01T22:17:03.527
Modified: 2026-10-01T22:17:03.527
Link: CVE-2026-51888
No data.
OpenCVE Enrichment
Updated: 2026-10-01T23:15:16Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')