HighVulnerability
CVE-2026-51888: langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-51888
- Published
- Record updated
Summary
A weakness in langflow-ai langflow up to 1.8.4 lets an attacker write or overwrite files outside the intended working directory. The flaw is an absolute path traversal in the knowledge base creation endpoint at src/backend/base/langflow/api/v1/knowledge_bases.py:51, reached over HTTP POST, and it is tracked as CVE-2026-51888.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database