Vulnerability  ·  2026-10-03

Langflow knowledge-base creation: absolute path traversal allows arbitrary file write outside the workspace

VulnerabilityMedium impactGlobalCVE-2026-51888
NVD published (2026-10-01) an absolute path traversal in Langflow's create-knowledge-base endpoint that allows writing or overwriting files outside the intended workspace via attacker-supplied absolute paths.
Knowledge bases are the RAG data store of Langflow deployments; a file-write primitive on the host can be chained toward persistence or overwriting application/config files in GenAI/agent environments.
An attacker supplies an absolute path to the knowledge-base creation endpoint, writing or overwriting files outside the intended working/storage directory on the Langflow server.
langflow-ai langflow up to 1.8.4 (create-knowledge-base handler, src/backend/base/langflow/api/v1/knowledge_bases.py)
Apply the vendor fix once available; do not expose the knowledge-base creation route to untrusted parties; run Langflow with a restricted service account.
NVD CVE-2026-51888
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →