CVE-2026-5027

HIGH EXPLOITED NUCLEI

Langflow - Path Traversal Arbitrary File Write via upload_user_file

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-5027 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 7 public exploits from researchers including EQSTLab, SecureWithUmer, HORKimhab. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-5027, demonstrating an arbitrary file write vulnerability in Langflow <= 1.8.4 via path traversal in the /api/v2/files endpoint, leading to unauthenticated RCE through cron job manipulation.

Description

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

Exploits (7)

nomisec WORKING POC 1 stars
by EQSTLab · remote-auth
https://github.com/EQSTLab/CVE-2026-5027

This repository contains a functional exploit for CVE-2026-5027, demonstrating an arbitrary file write vulnerability in Langflow <= 1.8.4 via path traversal in the /api/v2/files endpoint, leading to unauthenticated RCE through cron job manipulation.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Langflow <= 1.8.4
No auth needed
Prerequisites: Langflow instance with default auto-login configuration · network access to target
mistral-large-3 · analyzed Apr 08, 2026 Full analysis →
github WORKING POC
by SecureWithUmer · c++poc
https://github.com/SecureWithUmer/CVE-2026-PoCs/tree/main/2026/CVE-2026-5027

This repository contains a functional exploit for CVE-2026-5027, a path traversal vulnerability in Langflow <= 1.8.4 that allows unauthenticated arbitrary file write via the `/api/v2/files` endpoint. The exploit demonstrates remote code execution (RCE) by writing a cron job to achieve a reverse shell.

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Langflow <= 1.8.4
No auth needed
Prerequisites: Auto-login enabled (default configuration) or valid credentials · Target must be running a vulnerable version of Langflow (<= 1.8.4) · For RCE: Ability to write to cron directories or other sensitive paths
mistral-large-3 · analyzed Jul 08, 2026 Full analysis →
nomisec SUSPICIOUS
by HORKimhab · poc
https://github.com/HORKimhab/-CVE-2026-5027

The repository lacks functional exploit code for CVE-2026-5027 and instead contains a generic script for removing nested Git directories and a template README with no technical details about the vulnerability.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
Prerequisites: none
mistral-large-3 · analyzed Jun 11, 2026 Full analysis →
github WORKING POC
by Layer-6 · pythonremote
https://github.com/Layer-6/CVE-2026-5027-Langflow

This repository contains a functional exploit for CVE-2026-5027, targeting a path traversal vulnerability in Langflow. The exploit automates vulnerability detection, shell deployment (PHP/Python), privilege escalation, and post-exploitation actions like creating backdoor users and disabling firewalls.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Langflow (version not specified)
No auth needed
Prerequisites: Network access to the target Langflow instance · Python 3 environment
mistral-large-3 · analyzed Jun 11, 2026 Full analysis →
nomisec WORKING POC
by 0xBlackash · remote
https://github.com/0xBlackash/CVE-2026-5027

The repository contains a functional Python exploit for CVE-2026-5027, demonstrating a path traversal vulnerability in Langflow's file upload endpoint, leading to arbitrary file write and RCE via cron job injection.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Langflow <= 1.8.4
No auth needed
Prerequisites: Network access to target · Default or vulnerable Langflow installation
mistral-large-3 · analyzed Apr 08, 2026 Full analysis →
nomisec WORKING POC
by min8282 · poc
https://github.com/min8282/CVE-2026-5027

The repository contains a functional exploit for CVE-2026-5027, a path traversal vulnerability in Langflow <= 1.8.4. The exploit leverages insufficient sanitization of the 'filename' parameter in the `/api/v2/files` endpoint to achieve arbitrary file write, potentially leading to RCE in default configurations.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Langflow <= 1.8.4
No auth needed
Prerequisites: Network access to the target · Langflow instance with auto-login enabled (default) or valid credentials
mistral-large-3 · analyzed Apr 08, 2026 Full analysis →
nomisec WORKING POC
by yahiahamza · remote-auth
https://github.com/yahiahamza/CVE-2026-5027

The repository contains a functional exploit for CVE-2026-5027, demonstrating a path traversal vulnerability in Langflow <= 1.8.4 that leads to unauthenticated remote code execution via arbitrary file write. The exploit includes detailed technical analysis, root cause, and a working PoC script.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Langflow <= 1.8.4
No auth needed
Prerequisites: Target running Langflow <= 1.8.4 · Network access to the target's API endpoint
mistral-large-3 · analyzed Apr 08, 2026 Full analysis →

Nuclei Templates (1)

Langflow <= 1.8.4 - Path Traversal to RCE via File Upload
HIGHby pussycat0x
Shodan: title:"Langflow"
FOFA: title="Langflow"

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.3140
EPSS Percentile 98.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

VulnCheck KEV 2026-06-08
CWE
CWE-22
Status published
Products (1)
langflow-ai/langflow
Published Mar 27, 2026
Tracked Since Mar 29, 2026