SecBoard
Zurück zur CVE-Übersicht

CVE-2026-5027

HIGH(8.8)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Risk Signal Score33/100 — MITTEL
  • CVSS 8.8 — Hoch
  • EPSS 36%

Erwähnungen (letzte 60 Tage)

Artikel

EPSS-Score

36.1%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

8.8

Technische Schwere

Beschreibung

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../').

Betroffene Produkte

  • cpe:2.3:a:langflow:langflow:*:-:*:*:*:*:*:*

Referenzen