Langflow Path Traversal Vulnerability Allowing Arbitrary File Write

Vulnerability

A path traversal vulnerability has been identified in Langflow's 'POST /api/v2/files' endpoint. The issue arises because the endpoint does not properly sanitize the 'filename' parameter in the multipart form data. This lack of validation enables attackers to use path traversal sequences to write files to arbitrary locations on the filesystem.

Impact

Exploitation of this vulnerability could lead to unauthorized file writing on the server, potentially overwriting critical files or allowing the execution of malicious scripts, depending on the file type and location.

Added: Mar 27, 2026, 3:21 PM
Updated: Mar 27, 2026, 3:21 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
0.8
exploitability
4.9
remediation
0.0
relevance
4.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.