Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Langflow path traversal in Knowledge Bases API allows arbitrary directory deletion

CVE-2026-42048: Langflow versions prior to 1.9.0 concatenate user-supplied knowledge base names into file paths without sanitization in the DELETE /api/v1/knowledge_bases endpoint, letting an authenticated attacker delete arbitrary directories on the server. The issue is fixed in version 1.9.0.

Disclosed 12 May 2026 · Record updated 13 September 2026

Impact

An authenticated attacker could delete arbitrary directories anywhere on the server filesystem, causing data loss and potential service disruption.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42048