<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T07:07:04.385235+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-68478</id>
    <title>CVE-2025-68478 — Langflow Vulnerable to External Control of File Name or Path</title>
    <updated>2026-10-08T07:07:04.387257+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> langflow-ai langflow</p>
<p>Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.0, if an arbitrary path is specified in the request body's `fs_path`, the server serializes the Flow object into JSON and creates/overwrites a file at that path. There is no path restriction, normalization, or allowed directory enforcement, so absolute paths (e.g., /etc/poc.txt) are interpreted as is. Version 1.7.0 fixes the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-68478"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-f43r-cc68-gpx4</id>
    <title>GHSA-f43r-cc68-gpx4 — External Control of File Name or Path in Langflow</title>
    <updated>2026-10-08T07:07:04.387338+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: langflow</p>
<p>**Vulnerability Overview**</p>
<p>If an arbitrary path is specified in the request body's `fs_path`, the server serializes the Flow object into JSON and creates/overwrites a file at that path. There is no path restriction, normalization, or allowed directory enforcement, so absolute paths (e.g., /etc/poc.txt) are interpreted as is.</p>
<p>**Vulnerable Code**</p>
<p>1. It receives the request body (flow), updates the DB, and then passes it to the file-writing sink.
    
    https://github.com/langflow-ai/langflow/blob/ac6e2d2eabeee28085f2739d79f7ce4205ca082c/src/backend/base/langflow/api/v1/flows.py#L154-L168
    
    ```python
    @router.post("/", response_model=FlowRead, status_code=201)
    async def create_flow(
        *,
        session: DbSession,
        flow: FlowCreate,
        current_user: CurrentActiveUser,
    ):
        try:
            db_flow = await _new_flow(session=session, flow=flow, user_id=current_user.id)
            await session.commit()
            await session.refresh(db_flow)
    
            await _save_flow_to_fs(db_flow)
    
        except Exception as e:
    ```
    
2. Applies authentication dependency (requires API Key/JWT) when accessing the endpoint.
    
    https://github.com/langflow-ai/langflow/blob/ac6e2d2eabeee28085f2739d79f7ce4205ca082c/src/backend/base/langflow/api/utils/core.py#L36-L38
    
    ```python
    CurrentActiveUser = Annotated[User, Depends(get_current_active_user)]
    CurrentActiveMCPUser = Annotated[User, Depends(get_current_active…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-f43r-cc68-gpx4"/>
  </entry>
</feed>
