CVE-2026-51888: Path Traversal

Published Oct 1, 2026
·
Updated

langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundary.. The component is: src/backend/base/langflow/api/v1/knowledgebases.py:knowledgebases-createknowledgebase-a-live-http-post-to-create-knowledge-base. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing upload or HTTP route handler forwards an attacker-controlled path or filename into host file creation without any visible boundary enforcement. ¶¶ A weakness has been identified in langflow-ai langflow up to 1.8.4. langflow contains an absolute path traversal vulnerability in knowledgebases-createknowledgebase-a-live-http-post-to-create-knowledge-base (src/backend/base/langflow/api/v1/knowledgebases.py:51). An attacker can write or overwrite files outside the intended working directory by providing absolute paths in the knowledge base creation endpoint.

Affected Software

1 affected component
pypi/langflow<=1.8.4

Event History

Oct 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
Description

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments of langflow up to version 1.8.4 are exposed where an attacker can reach the knowledge base creation HTTP endpoint. The described attack surface is a public-facing upload or HTTP route handler.

2

What does an attacker need to exploit it?

An attacker needs the ability to submit a request to create a knowledge base and supply an attacker-controlled absolute path or filename. The vulnerability is in the handling of that path during host file creation.

3

What could an attacker do through successful exploitation?

An attacker can write or overwrite files outside the intended workspace or storage boundary. The specific files that can be affected depend on the permissions of the process running langflow.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203