Executive brief
Langflow, a framework for building multi-agent AI applications, contains a vulnerability that allows authenticated users to write files to arbitrary locations on the server. By providing a specific file path when creating a 'Flow,' an attacker can overwrite critical system or application files with JSON data. This could lead to service disruptions, corruption of configuration files, or unauthorized modification of application data.
Technical details
An arbitrary file write vulnerability exists in Langflow's flow creation endpoint due to insufficient validation of the 'fs_path' parameter. When a user creates a flow, the backend uses the user-provided path in the '_save_flow_to_fs' function without normalization or directory restriction. An authenticated attacker with a valid API key or JWT can provide absolute or relative paths (e.g., /tmp/POC.txt) to create or overwrite files with the serialized JSON representation of the Flow object. While the content is restricted to JSON, the ability to overwrite arbitrary files within the application's process permissions can lead to integrity loss or denial of service. This issue is addressed in version 1.7.1.
Affected products
- langflow-ai langflow < 1.7.1
Timeline
- 2025-12-19: disclosed
- 2025-12-19: advisory
- 1.7.1: patched