langflow is vulnerable to Path Traversal
88
High Risk
POST /api/v2/files (upload_user_file) takes the multipart filename and uses it when storing the upload without rejecting path separators or ../ segments. An authenticated attacker can therefore write uploaded content outside the intended user file directory to an arbitrary filesystem location the process can reach. The fix validates and sanitizes the multipart filename so traversal sequences and path separators are rejected before storage.
You are affected if you are using a version that falls within the vulnerable range and authenticated users can call the file upload API.
langflow is vulnerable to Path Traversal in versions 0.0.31 - 1.8.4.
Upgrade the langflow library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.