OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-51888

HIGH · CVSS 7.5 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Langflow AI versions up to 1.8.4 are vulnerable to a directory traversal attack, allowing an attacker to write or overwrite files outside the designated workspace through the knowledge base creation endpoint. This flaw arises from insufficient boundary enforcement in the HTTP request handling, potentially leading to unauthorized file manipulation on the host system. Organizations using this software, especially those with public-facing services, should prioritize remediation to mitigate the risk of arbitrary file writes.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51888
Severity
HIGH
CVSS
7.5
EPSS
0.23%

Original NVD Description

langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundary.. The component is: src/backend/base/langflow/api/v1/knowledge_bases.py:knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing upload or HTTP route handler forwards an attacker-controlled path or filename into host file creation without any visible boundary enforcement. ΒΆΒΆ A weakness has been identified in langflow-ai langflow up to 1.8.4. langflow contains an absolute path traversal vulnerability in knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base (src/backend/base/langflow/api/v1/knowledge_bases.py:51). An attacker can write or overwrite files outside the intended working directory by providing absolute paths in the knowledge base creation endpoint.