Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 02 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langflow
Langflow langflow |
|
| Vendors & Products |
Langflow
Langflow langflow |
Thu, 01 Oct 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Directory Traversal Allowing Arbitrary File Write in Langflow Knowledge Base Creation Endpoint | |
| Weaknesses | CWE-22 |
Thu, 01 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundary.. The component is: src/backend/base/langflow/api/v1/knowledge_bases.py:knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base. The attack vector is: Attack surface: HTTP or browser-backed service path. A public-facing upload or HTTP route handler forwards an attacker-controlled path or filename into host file creation without any visible boundary enforcement. ¶¶ A weakness has been identified in langflow-ai langflow up to 1.8.4. langflow contains an absolute path traversal vulnerability in knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base (src/backend/base/langflow/api/v1/knowledge_bases.py:51). An attacker can write or overwrite files outside the intended working directory by providing absolute paths in the knowledge base creation endpoint. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-06T14:20:43.933Z
Reserved: 2026-06-08T00:00:00.000Z
Link: CVE-2026-51888
Updated: 2026-10-06T14:18:43.104Z
Status : Awaiting Analysis
Published: 2026-10-01T22:17:03.527
Modified: 2026-10-06T15:17:18.300
Link: CVE-2026-51888
No data.
OpenCVE Enrichment
Updated: 2026-10-02T14:30:23Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')