{"data":{"id":"87b98c16-9111-4234-bf00-5f112a280abe","title":"CVE-2026-51888: langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the…","summary":"A weakness in langflow-ai langflow up to 1.8.4 lets an attacker write or overwrite files outside the intended working directory. The flaw is an absolute path traversal in the knowledge base creation endpoint at src/backend/base/langflow/api/v1/knowledge_bases.py:51, reached over HTTP POST, and it is tracked as CVE-2026-51888.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-51888","publishedAt":"2026-10-01T22:17:03.527Z","cveId":"CVE-2026-51888","cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["Langflow"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00563,"epssCheckedAt":"2026-10-10T06:42:01.794Z","kevDateAdded":null,"advisoryAliases":["GHSA-5rwq-2vwh-7g73"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:43:02.742Z","patchAvailable":null,"disclosureDate":"2026-10-01T22:17:03.527Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0010"]}}