<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T08:16:16.851151+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-42048</id>
    <title>CVE-2026-42048 — Langflow: Path Traversal in Langflow Knowledge Bases API</title>
    <updated>2026-10-04T08:16:16.852934+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> langflow-ai langflow</p>
<p>Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are concatenated directly into file paths without proper sanitization or boundary validation. An authenticated attacker can exploit this flaw to delete arbitrary directories anywhere on the server's filesystem, leading to data loss and potential service disruption. This vulnerability is fixed in 1.9.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-42048"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9whx-c884-c68q</id>
    <title>GHSA-9whx-c884-c68q — Langflow Knowledge Bases API is Vulnerable to Path Traversal</title>
    <updated>2026-10-04T08:16:16.852990+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: langflow</p>
<p>## Summary
Langflow is vulnerable to Path Traversal in the Knowledge Bases API (`DELETE /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are concatenated directly into file paths without proper sanitization or boundary validation. An authenticated attacker can exploit this flaw to delete arbitrary directories anywhere on the server's filesystem, leading to data loss and potential service disruption.</p>
<p>## Details
The vulnerability exists in the `delete_knowledge_bases_bulk` function within `src/backend/base/langflow/api/v1/knowledge_bases.py`.</p>
<p>This function constructs file paths directly from the user-supplied `kb_names` parameter. While other knowledge base endpoints safely route through standard path resolution (e.g., `_resolve_kb_path()`), the bulk delete handler bypasses this entirely. It builds the path manually and passes it directly to `shutil.rmtree()` without validating if the resulting path resolves outside the intended user directory.</p>
<p>## PoC (Proof of Concept)
For the **Bulk Delete** endpoint, an authenticated attacker can supply a traversal sequence in the `kb_names` parameter:
`../victim_user/kb_name`</p>
<p>Because the path is passed directly to `shutil.rmtree()` without containment checks, this payload deletes directories outside the intended scope.</p>
<p>## Impact
Any Langflow instance exposing this endpoint to authenticated users is vulnerable. This exposes the server to:
* **Cross-user data compromise:** Deletion of directories within…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9whx-c884-c68q"/>
  </entry>
</feed>
