CVE-2026-5027 | langflow-ai langflow Multipart Form Data Parser /api/v2/files filename path traversal
A vulnerability labeled as critical has been found in langflow-ai langflow. This affects an unknown function of the file /api/v2/files of the component Multipart Form Data Parser. Executing a manipulation of the argument filename can lead to path traversal.
The identification of this vulnerability is CVE-2026-5027. The attack may be launched remotely. There is no exploit available.