VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_efdaae8518c88b1dc83967c291dfc963

Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE

Published Jun 10, 2026

A high-severity security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitation in the wild, according to findings from VulnCheck.

The vulnerability in question is CVE-2026-5027 (CVSS score: 8.8), a case of path traversal that could allow an attacker to write files to arbitrary locations.

"The 'POST /api/v2/

Affected AI Products

langflow
Get the weekly digest. Every Monday: top AI security stories of the week. Free.