The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').
https://www.securityweek.com/hackers-start-exploiting-critical-langflow-vulnerability/
https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html
https://www.vulncheck.com/blog/pwning-the-ai-stack
https://thehackernews.com/2026/07/cisa-adds-4-actively-exploited-adobe.html
https://www.securityweek.com/hackers-exploit-langflow-vulnerability-for-remote-code-execution/
https://thehackernews.com/2026/06/unpatched-langflow-flaw-cve-2026-5027.html