What happened
NVD published (2026-10-01) an absolute path traversal in Langflow's create-knowledge-base endpoint that allows writing or overwriting files outside the intended workspace via attacker-supplied absolute paths.
Why it matters
Knowledge bases are the RAG data store of Langflow deployments; a file-write primitive on the host can be chained toward persistence or overwriting application/config files in GenAI/agent environments.
Attack vector
An attacker supplies an absolute path to the knowledge-base creation endpoint, writing or overwriting files outside the intended working/storage directory on the Langflow server.
Affected systems
langflow-ai langflow up to 1.8.4 (create-knowledge-base handler, src/backend/base/langflow/api/v1/knowledge_bases.py)
Mitigation
Apply the vendor fix once available; do not expose the knowledge-base creation route to untrusted parties; run Langflow with a restricted service account.