Junglewise Threat Intelligence

CVE-2026-42867: Langflow path traversal in Knowledge Bases API

CVE-2026-42867 · Severity: medium · CVSS 6.5 · Published 2026-06-23

Technologies: Langflow-Ai Langflow, langflow (PyPI). Vendors: PyPI.

Executive brief

Langflow is a platform used to build and deploy AI-powered workflows and agents. A security flaw in its Knowledge Bases component allows users to bypass folder restrictions by providing specially crafted names. This could allow an attacker to create unauthorized folders or overwrite specific configuration files elsewhere on the server, potentially leading to data corruption or interference with other users' work.

Technical details

A path traversal vulnerability exists in the `create_knowledge_base` function within `src/backend/base/langflow/api/v1/knowledge_bases.py`. The `POST /api/v1/knowledge_bases` endpoint fails to sanitize the user-supplied `name` field before using it to construct file paths via `kb_path.mkdir()`. An attacker can use traversal sequences (e.g., `../`) or absolute paths to create directories and write application-specific files (`embedding_metadata.json` and `schema.json`) outside the intended root directory. This can result in cross-user data compromise or arbitrary filesystem manipulation. The issue is resolved in version 1.9.0 by implementing strict path validation using `Path.is_relative_to()`.

Affected products

  • langflow-ai Langflow < 1.9.0

Timeline

  • 2026-03-26: patched: Fix merged into release-1.9.0 branch
  • 2026-06-11: advisory: GitHub Security Advisory published
  • 2026-06-23: disclosed: CVE published to NVD

References

Related threats