Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE
According to VulnCheck, a high-severity unpatched security vulnerability in Langflow, an open-source low-code platform for creating artificial intelligence (AI) applications, has been actively exploited in the wild.
The vulnerability in question is CVE-2026-5027 (CVSS score: 8.8), a path traversal situation that can enable an attacker to write files to any location.Tenable, which found the vulnerability, stated in an alert published in late March 2026 that the 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').
Before revealing the specifics of the problem on March 27, the cybersecurity firm claimed to have made three...


