<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:48:16 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-317992</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-317992</link>
      <description>EUVD-2026-317992</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-317992</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42048</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42048</link>
      <description>&lt;p&gt;Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are concatenated directly into file paths without proper sanitization or boundary validation. An authenticated attacker can exploit this flaw to delete arbitrary directories anywhere on the server&amp;#39;s filesystem, leading to data loss and potential service disruption. This vulnerability is fixed in 1.9.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (DELETE /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are concatenated directly into file paths without proper sanitization or boundary validation. An authenticated attacker can exploit this flaw to delete arbitrary directories anywhere on the server&amp;#39;s filesystem, leading to data loss and potential service disruption. This vulnerability is fixed in 1.9.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42048</guid>
    </item>
    <item>
      <title>GHSA-9whx-c884-c68q — Langflow Knowledge Bases API is Vulnerable to Path Traversal</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9whx-c884-c68q</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;## Summary
Langflow is vulnerable to Path Traversal in the Knowledge Bases API (`DELETE /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are concatenated directly into file paths without proper sanitization or boundary validation. An authenticated attacker can exploit this flaw to delete arbitrary directories anywhere on the server&amp;#39;s filesystem, leading to data loss and potential service disruption.&lt;/p&gt;
&lt;p&gt;## Details
The vulnerability exists in the `delete_knowledge_bases_bulk` function within `src/backend/base/langflow/api/v1/knowledge_bases.py`.&lt;/p&gt;
&lt;p&gt;This function constructs file paths directly from the user-supplied `kb_names` parameter. While other knowledge base endpoints safely route through standard path resolution (e.g., `_resolve_kb_path()`), the bulk delete handler bypasses this entirely. It builds the path manually and passes it directly to `shutil.rmtree()` without validating if the resulting path resolves outside the intended user directory.&lt;/p&gt;
&lt;p&gt;## PoC (Proof of Concept)
For the **Bulk Delete** endpoint, an authenticated attacker can supply a traversal sequence in the `kb_names` parameter:
`../victim_user/kb_name`&lt;/p&gt;
&lt;p&gt;Because the path is passed directly to `shutil.rmtree()` without containment checks, this payload deletes directories outside the intended scope.&lt;/p&gt;
&lt;p&gt;## Impact
Any Langflow instance exposing this endpoint to authenticated users is vulnerable. This exposes the server to:
* **Cross-user data compromise:** Deletion of directories within…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;## Summary
Langflow is vulnerable to Path Traversal in the Knowledge Bases API (`DELETE /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are concatenated directly into file paths without proper sanitization or boundary validation. An authenticated attacker can exploit this flaw to delete arbitrary directories anywhere on the server&amp;#39;s filesystem, leading to data loss and potential service disruption.&lt;/p&gt;
&lt;p&gt;## Details
The vulnerability exists in the `delete_knowledge_bases_bulk` function within `src/backend/base/langflow/api/v1/knowledge_bases.py`.&lt;/p&gt;
&lt;p&gt;This function constructs file paths directly from the user-supplied `kb_names` parameter. While other knowledge base endpoints safely route through standard path resolution (e.g., `_resolve_kb_path()`), the bulk delete handler bypasses this entirely. It builds the path manually and passes it directly to `shutil.rmtree()` without validating if the resulting path resolves outside the intended user directory.&lt;/p&gt;
&lt;p&gt;## PoC (Proof of Concept)
For the **Bulk Delete** endpoint, an authenticated attacker can supply a traversal sequence in the `kb_names` parameter:
`../victim_user/kb_name`&lt;/p&gt;
&lt;p&gt;Because the path is passed directly to `shutil.rmtree()` without containment checks, this payload deletes directories outside the intended scope.&lt;/p&gt;
&lt;p&gt;## Impact
Any Langflow instance exposing this endpoint to authenticated users is vulnerable. This exposes the server to:
* **Cross-user data compromise:** Deletion of directories within…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9whx-c884-c68q</guid>
    </item>
    <item>
      <title>PYSEC-2026-377 — Langflow Knowledge Bases API is Vulnerable to Path Traversal</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-377</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;## Summary
Langflow is vulnerable to Path Traversal in the Knowledge Bases API (`DELETE /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are concatenated directly into file paths without proper sanitization or boundary validation. An authenticated attacker can exploit this flaw to delete arbitrary directories anywhere on the server&amp;#39;s filesystem, leading to data loss and potential service disruption.&lt;/p&gt;
&lt;p&gt;## Details
The vulnerability exists in the `delete_knowledge_bases_bulk` function within `src/backend/base/langflow/api/v1/knowledge_bases.py`.&lt;/p&gt;
&lt;p&gt;This function constructs file paths directly from the user-supplied `kb_names` parameter. While other knowledge base endpoints safely route through standard path resolution (e.g., `_resolve_kb_path()`), the bulk delete handler bypasses this entirely. It builds the path manually and passes it directly to `shutil.rmtree()` without validating if the resulting path resolves outside the intended user directory.
 
## PoC (Proof of Concept)
For the **Bulk Delete** endpoint, an authenticated attacker can supply a traversal sequence in the `kb_names` parameter:
`../victim_user/kb_name`
 
Because the path is passed directly to `shutil.rmtree()` without containment checks, this payload deletes directories outside the intended scope.&lt;/p&gt;
&lt;p&gt;## Impact
Any Langflow instance exposing this endpoint to authenticated users is vulnerable. This exposes the server to:
* **Cross-user data compromise:** Deletion of directories with…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: langflow&lt;/p&gt;
&lt;p&gt;## Summary
Langflow is vulnerable to Path Traversal in the Knowledge Bases API (`DELETE /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are concatenated directly into file paths without proper sanitization or boundary validation. An authenticated attacker can exploit this flaw to delete arbitrary directories anywhere on the server&amp;#39;s filesystem, leading to data loss and potential service disruption.&lt;/p&gt;
&lt;p&gt;## Details
The vulnerability exists in the `delete_knowledge_bases_bulk` function within `src/backend/base/langflow/api/v1/knowledge_bases.py`.&lt;/p&gt;
&lt;p&gt;This function constructs file paths directly from the user-supplied `kb_names` parameter. While other knowledge base endpoints safely route through standard path resolution (e.g., `_resolve_kb_path()`), the bulk delete handler bypasses this entirely. It builds the path manually and passes it directly to `shutil.rmtree()` without validating if the resulting path resolves outside the intended user directory.
 
## PoC (Proof of Concept)
For the **Bulk Delete** endpoint, an authenticated attacker can supply a traversal sequence in the `kb_names` parameter:
`../victim_user/kb_name`
 
Because the path is passed directly to `shutil.rmtree()` without containment checks, this payload deletes directories outside the intended scope.&lt;/p&gt;
&lt;p&gt;## Impact
Any Langflow instance exposing this endpoint to authenticated users is vulnerable. This exposes the server to:
* **Cross-user data compromise:** Deletion of directories with…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-377</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-1284 — Langflow: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1284</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Langflow ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Langflow ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1284</guid>
    </item>
  </channel>
</rss>
