Langflow path traversal in Knowledge Bases API allows arbitrary directory deletion
CVE-2026-42048: Langflow versions prior to 1.9.0 concatenate user-supplied knowledge base names into file paths without sanitization in the DELETE /api/v1/knowledge_bases endpoint, letting an authenticated attacker delete arbitrary directories on the server. The issue is fixed in version 1.9.0.
Disclosed 12 May 2026 · Record updated 13 September 2026
Impact
An authenticated attacker could delete arbitrary directories anywhere on the server filesystem, causing data loss and potential service disruption.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42048
