CVE-2026-5027
HIGH EXPLOITED NUCLEILangflow - Path Traversal Arbitrary File Write via upload_user_file
Title source: cnaExploitation Summary
CVE-2026-5027 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 7 public exploits from researchers including EQSTLab, SecureWithUmer, HORKimhab. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-5027, demonstrating an arbitrary file write vulnerability in Langflow <= 1.8.4 via path traversal in the /api/v2/files endpoint, leading to unauthenticated RCE through cron job manipulation.
Description
The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').
Exploits (7)
This repository contains a functional exploit for CVE-2026-5027, demonstrating an arbitrary file write vulnerability in Langflow <= 1.8.4 via path traversal in the /api/v2/files endpoint, leading to unauthenticated RCE through cron job manipulation.
This repository contains a functional exploit for CVE-2026-5027, a path traversal vulnerability in Langflow <= 1.8.4 that allows unauthenticated arbitrary file write via the `/api/v2/files` endpoint. The exploit demonstrates remote code execution (RCE) by writing a cron job to achieve a reverse shell.
The repository lacks functional exploit code for CVE-2026-5027 and instead contains a generic script for removing nested Git directories and a template README with no technical details about the vulnerability.
This repository contains a functional exploit for CVE-2026-5027, targeting a path traversal vulnerability in Langflow. The exploit automates vulnerability detection, shell deployment (PHP/Python), privilege escalation, and post-exploitation actions like creating backdoor users and disabling firewalls.
The repository contains a functional Python exploit for CVE-2026-5027, demonstrating a path traversal vulnerability in Langflow's file upload endpoint, leading to arbitrary file write and RCE via cron job injection.
The repository contains a functional exploit for CVE-2026-5027, a path traversal vulnerability in Langflow <= 1.8.4. The exploit leverages insufficient sanitization of the 'filename' parameter in the `/api/v2/files` endpoint to achieve arbitrary file write, potentially leading to RCE in default configurations.
The repository contains a functional exploit for CVE-2026-5027, demonstrating a path traversal vulnerability in Langflow <= 1.8.4 that leads to unauthenticated remote code execution via arbitrary file write. The exploit includes detailed technical analysis, root cause, and a working PoC script.
Nuclei Templates (1)
title:"Langflow"
title="Langflow"
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H