# CVE-2026-5027 — langflow-ai langflow

> As of 2026-03-27, CVE-2026-5027 is a HIGH-severity vulnerability in langflow-ai langflow, CVSS v3.1 8.8, EPSS 4.7% (91.5th percentile). Threadlinqs Intelligence links 3 tracked threat campaigns to CVE-2026-5027, most recently “GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027”.

**Last updated:** 2026-03-27

## What is CVE-2026-5027?

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

The record classifies CVE-2026-5027 under weakness class [CWE-22](https://cwe.mitre.org/data/definitions/22.html). Its CVSS v3 base vector states that the flaw is reachable remotely over the network, needs low-privilege credentials, needs no user interaction, and has high impact on confidentiality, integrity, availability. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 188 days ago.

## Severity and exploitation probability

- **CVSS v3.1 base score:** 8.8 — HIGH (`CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H`)
- **EPSS (FIRST):** 4.7% probability of exploitation in the next 30 days, higher than 91.5% of all scored CVEs
- **CISA KEV:** Not listed in the CISA Known Exploited Vulnerabilities catalog
- **Threadlinqs priority:** 10/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- **Published:** 2026-03-27

## Is CVE-2026-5027 being exploited?

Weaponised exploit code for CVE-2026-5027 is publicly available. 8 public proof-of-concept repositories are tracked for this identifier. A ProjectDiscovery Nuclei detection template exists (`http/cves/2026/CVE-2026-5027.yaml`).

- [yahiahamza/CVE-2026-5027](https://github.com/yahiahamza/CVE-2026-5027) (github)
- [EQSTLab/CVE-2026-5027](https://github.com/EQSTLab/CVE-2026-5027) (github)
- [yym8538/CVE-2026-5027](https://github.com/yym8538/CVE-2026-5027) (github)
- [min8282/CVE-2026-5027](https://github.com/min8282/CVE-2026-5027) (github)
- [0xBlackash/CVE-2026-5027](https://github.com/0xBlackash/CVE-2026-5027) (github)
- [Layer-6/CVE-2026-5027-Langflow](https://github.com/Layer-6/CVE-2026-5027-Langflow) (github)
- [HORKimhab/CVE-2026-5027](https://github.com/HORKimhab/CVE-2026-5027) (github)
- [rmhowe425/POC-CVE-2026-5027](https://github.com/rmhowe425/POC-CVE-2026-5027) (github)

## Affected products and versions

- **langflow-ai**: langflow

## How to fix CVE-2026-5027

Vendor advisory: [https://www.tenable.com/security/research/tra-2026-26](https://www.tenable.com/security/research/tra-2026-26). Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.

## Threat activity tracking CVE-2026-5027

3 tracked threats in the Threadlinqs corpus reference CVE-2026-5027, either in the campaign’s CVE list or as an indicator on the campaign record.

- [GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust CVE-2026-1731, LiteLLM CVE-2026-42271 and Langflow CVE-2026-5027](https://intel.threadlinqs.com/threat/TL-2026-2818) — CRITICAL · 2026-09-30
- [CVE-2025-3248 & CVE-2026-5027: Langflow RCE and Path Traversal Chained for Flodrix Botnet Deployment](https://intel.threadlinqs.com/threat/TL-2026-1247) — CRITICAL · 2026-07-12
- [CVE-2026-5027: Path Traversal Arbitrary File Write in Langflow AI Dev Platform (upload_user_file) Exploited in the Wild for Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-0766) — HIGH · 2026-06-10

## Sources

Enriched from CVE.org, NVD, FIRST EPSS, GitHub Security Advisories, public proof-of-concept repositories, ProjectDiscovery Nuclei. Last verified by Threadlinqs on 2026-10-01. This product uses the NVD API but is not endorsed or certified by the NVD.

**Other references**

- [tenable.com](https://www.tenable.com/security/research/tra-2026-26)

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-5027
Full detection coverage and IOCs for threats exploiting CVE-2026-5027 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
