Langflow
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*
A path traversal vulnerability has been identified in Langflow's 'POST /api/v2/files' endpoint. The issue arises because the endpoint does not properly sanitize the 'filename' parameter in the multipart form data. This lack of validation enables attackers to use path traversal sequences to write files to arbitrary locations on the filesystem.
Exploitation of this vulnerability could lead to unauthorized file writing on the server, potentially overwriting critical files or allowing the execution of malicious scripts, depending on the file type and location.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.