Developing event. Generated by AI and subject to further corroboration and review.
Path traversal vulnerability in Langflow AI platform actively exploited
CVE-2026-5027, a high-severity unauthenticated path traversal vulnerability in the Langflow AI development platform, is being actively exploited. Exploitation evidence to date is limited to test-file drops observed on honeypots; no insured losses, breach notifications, or claims activity have been confirmed. Roughly 7,000 Langflow instances have been identified as publicly exposed, and a fix is available in Langflow 1.10.0. Materiality depends on patch adoption and whether exploitation progresses beyond initial access.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Medium impact. Loss pathway is cyber. Unauthenticated exploitation of a widely deployed AI development platform, combined with default unauthenticated auto-login and a history of prior Langflow CVEs being exploited (including a CISA-noted link to the Iranian state-sponsored group MuddyWater), raises the ceiling of potential accumulation risk. Counterweights: no confirmed insured losses, breach notifications, or claims activity, and exploitation evidence to date is limited to test file drops detected in honeypots. Materiality depends on patch adoption rates among the exposed footprint and whether exploitation progresses beyond initial access. Relevant to cyber underwriters monitoring accumulation risk across AI/tech insureds and to incident-response capacity planning.
View assessment methodologyHow we grade what we know -- Known · Reported · Uncertain. Methodology →
Intelligence ledger
Each line expands in place to its underlying sourced claim.
Known41 lines
CVE-2026-5027 is a high-severity path traversal vulnerability in Langflow's file upload functionality▾
Langflow enables unauthenticated auto-login by default, making exploitation possible without credentials▾
VulnCheck honeypots have detected active exploitation dropping test files on vulnerable instances▾
A patch was released in Langflow version 1.10.0▾
Tenable publicly disclosed the issue on March 27, 2026 after reporting to Langflow team without response▾
Earlier Langflow CVEs (CVE-2026-0770, CVE-2026-21445, CVE-2026-33017, CVE-2025-3248) have also been actively exploited▾
CISA previously warned about exploitation of CVE-2025-3248 linked to Iranian threat group MuddyWater▾
Tenable publicly disclosed CVE-2026-5027 on March 27, 2026 after reporting to the Langflow team without response.▾
Langflow enables unauthenticated auto-login by default, allowing exploitation without credentials; a single unauthenticated request yields a valid session token.▾
Tenable publicly disclosed CVE-2026-5027 on March 27, 2026 after reporting to the Langflow team without response.▾
Earlier Langflow CVEs (CVE-2026-0770, CVE-2026-21445, CVE-2026-33017, CVE-2025-3248) have also been actively exploited.▾
Tenable publicly disclosed CVE-2026-5027 on 27 March 2026 after reporting the issue to the Langflow team without response.▾
Langflow enables unauthenticated auto-login by default, so no credentials are required to reach the vulnerable endpoint.▾
Tenable publicly disclosed CVE-2026-5027 on 27 March 2026 after reporting to the Langflow maintainers without receiving a response.▾
Earlier Langflow CVEs (CVE-2026-0770, CVE-2026-21445, CVE-2026-33017, CVE-2025-3248) have also been actively exploited; CISA previously warned about exploitation of CVE-2025-3248 linked to Iranian threat group MuddyWater.▾
CISA previously warned that exploitation of CVE-2025-3248 in Langflow has been linked to Iranian state-sponsored threat group MuddyWater.▾
Earlier Langflow CVEs (CVE-2026-0770, CVE-2026-21445, CVE-2026-33017, CVE-2025-3248) have also been actively exploited, indicating a recurring pattern of high-impact flaws in the platform.▾
CVE-2026-5027 is a high-severity unauthenticated path traversal vulnerability in the Langflow AI development platform's file upload functionality.▾
Active exploitation of CVE-2026-5027 has been observed, with VulnCheck honeypots detecting test-file drops on vulnerable instances.▾
CVE-2026-5027 is a high-severity unauthenticated path traversal vulnerability in Langflow's file upload functionality.▾
VulnCheck honeypots have detected active exploitation of CVE-2026-5027, with attackers dropping test files on vulnerable instances.▾
Langflow enables unauthenticated auto-login by default, meaning no credentials are required to reach the vulnerable endpoint.▾
CVE-2026-5027 is a high-severity unauthenticated path traversal vulnerability in Langflow's file upload functionality.▾
Langflow enables unauthenticated auto-login by default, allowing exploitation of CVE-2026-5027 without credentials; a single unauthenticated request can obtain a valid session token.▾
CVE-2026-5027 is a high-severity unauthenticated path traversal vulnerability in the Langflow AI development platform's file upload functionality.▾
Langflow enables unauthenticated auto-login by default, allowing a single unauthenticated request to obtain a valid session token and reach the vulnerable endpoint.▾
CVE-2026-5027 is a high-severity path traversal vulnerability in Langflow's file upload functionality.▾
VulnCheck honeypots have detected active exploitation of CVE-2026-5027, with observed activity limited to dropping test files on vulnerable instances.▾
Langflow enables unauthenticated auto-login by default, so no credentials are required to reach the vulnerable endpoint; a single unauthenticated request can obtain a valid session token before exploitation.▾
No insured losses, breach notifications, or claims activity have been confirmed in connection with CVE-2026-5027.▾
A fix for CVE-2026-5027 is available in Langflow version 1.10.0.▾
No insured losses, breach notifications, or claims activity have been confirmed in connection with CVE-2026-5027 at this stage.▾
A fix for CVE-2026-5027 is available in Langflow version 1.10.0.▾
VulnCheck honeypots have detected active exploitation of CVE-2026-5027, with attackers dropping test files on vulnerable instances.▾
A patch has been released in Langflow version 1.10.0 to address CVE-2026-5027.▾
CVE-2026-5027 is being actively exploited, with VulnCheck honeypots detecting exploitation that drops test files on vulnerable instances.▾
Tenable publicly disclosed CVE-2026-5027 on March 27, 2026 after reporting to the Langflow team without response.▾
A fix for CVE-2026-5027 is available in Langflow version 1.10.0.▾
A patch addressing CVE-2026-5027 is available in Langflow version 1.10.0.▾
The event is in 'signal' lifecycle status, indicating early-stage intelligence with active exploitation observed but no confirmed insured losses.▾
VulnCheck honeypots have detected active exploitation of CVE-2026-5027, with observed activity dropping test files on vulnerable instances.▾
Reported17 lines
Censys identified roughly 7,000 publicly exposed Langflow instances, though figure may include historical data▾
Langflow has accumulated 149,000+ stars and 9,200 forks on GitHub indicating wide adoption▾
CISA previously warned about exploitation of CVE-2025-3248 linked to the Iranian state-sponsored threat group MuddyWater.▾
Langflow has accumulated more than 149,000 GitHub stars and 9,200 forks, indicating wide adoption.▾
A German-language GDELT-translated source (blogspan.net) corroborates that CVE-2026-5027 is being actively exploited and recommends immediate patching.▾
Earlier Langflow CVEs (CVE-2026-0770, CVE-2026-21445, CVE-2026-33017, CVE-2025-3248) have also been actively exploited.▾
Censys scans have identified roughly 7,000 publicly exposed Langflow instances; the figure may include historical data.▾
CISA previously warned that exploitation of CVE-2025-3248 has been linked to Iranian state-sponsored group MuddyWater.▾
Langflow has accumulated more than 149,000 GitHub stars and 9,200 forks, indicating wide developer adoption.▾
Langflow has accumulated 149,000+ stars and 9,200 forks on GitHub, indicating wide adoption among AI developers.▾
CISA previously warned about exploitation of CVE-2025-3248 in Langflow, with reporting linking activity to Iranian state-sponsored group MuddyWater.▾
Censys identified approximately 7,000 publicly exposed Langflow instances, though the figure may include historical data.▾
CISA previously warned about exploitation of CVE-2025-3248 in Langflow, linked to the Iranian state-sponsored threat group MuddyWater.▾
Langflow has accumulated more than 149,000 GitHub stars and 9,200 forks, indicating wide developer adoption.▾
Censys identified approximately 7,000 publicly exposed Langflow instances, though the figure may include historical data.▾
Censys scans identified roughly 7,000 publicly exposed Langflow instances, though the figure may include historical data.▾
The loss pathway is cyber; exploitation could enable ransomware staging, data exfiltration, and lateral movement into corporate networks, particularly where Langflow is deployed in enterprise environments.▾
Uncertain18 lines
Actual number of currently exposed and vulnerable Langflow instances▾
Scale of successful exploitation beyond honeypot detection▾
Whether any Langflow-using organizations have suffered confirmed breaches or data loss▾
Total cyber insurance claim exposure from this vulnerability▾
The actual number of currently exposed and vulnerable Langflow instances is unconfirmed; the Censys figure may include historical or non-vulnerable exposures.▾
The scale of successful exploitation beyond honeypot detection of test file drops is not known.▾
The actual number of currently exposed and unpatched Langflow instances is not known.▾
The actual number of Langflow instances currently exposed AND running a vulnerable version is unconfirmed; Censys exposure figures may include historical/honey data.▾
It is unconfirmed whether exploitation of CVE-2026-5027 has progressed beyond test file drops to ransomware deployment, data exfiltration, or other high-impact outcomes.▾
The actual number of currently exposed and vulnerable Langflow instances is uncertain; the 7,000 figure may include historical data.▾
No insured losses, breach notifications, or claims activity have been confirmed in connection with CVE-2026-5027 at this stage.▾
Total cyber insurance claim exposure from this vulnerability is unquantified.▾
Total cyber insurance claim exposure from CVE-2026-5027 remains unquantified.▾
Materiality depends on the share of organizations still running vulnerable Langflow versions and whether exploitation progresses beyond initial access.▾
The actual number of currently exposed and vulnerable Langflow instances is uncertain; the Censys 7,000 figure may include historical data.▾
It is not known whether any Langflow-using organizations have suffered confirmed breaches or data loss as a result of CVE-2026-5027.▾
The scale of successful exploitation beyond honeypot detection is not yet known.▾
Whether any Langflow-using organizations have suffered confirmed breaches or data loss is unconfirmed.▾
Latest developments
- CVE-2026-5027 is a high-severity unauthenticated path traversal flaw in Langflow. — BleepingComputer
- Exploitation is active; honeypots have observed test-file drops. — BleepingComputer
- Default configuration permits unauthenticated access, raising exploitability. — BleepingComputer
- A fix is available in Langflow 1.10.0. — BleepingComputer
- Around 7,000 Langflow instances are reported as publicly exposed (figure may include historical data). — BleepingComputer
- Tenable disclosed the issue publicly on March 27, 2026 after the Langflow team did not respond. — BleepingComputer
- Multiple prior Langflow CVEs have also been actively exploited. — BleepingComputer
- CISA has previously linked exploitation of a prior Langflow CVE to Iranian group MuddyWater. — BleepingComputer
Timeline
Status changed to developing
evidence_trigger: corroboration >= 2
signal -> developing
A critical path traversal vulnerability (CVE-2026-5027) in Langflow, an open-source AI workflow platform, is being actively exploited in the wild, enabling remote code execution. Immediate patching is advised. The vulnerability poses a supply-chain risk for enterprises and organizations using Langflow in production environments, with potential implications for cyber insurance underwriting and incident response.
Source: blogspan.net (Mainstream Media) · View source
Initial Detection
Attackers are actively exploiting CVE-2026-5027, a high-severity unauthenticated path traversal flaw in the widely-used AI development platform Langflow, to write arbitrary files on exposed servers. Approximately 7,000 Langflow instances were identified as publicly exposed via Censys scans, creating potential cyber exposure for organizations using the platform for AI development. The vulnerability requires no authentication due to default auto-login settings and a patch is available in version 1.10.0.
Because Langflow enables unauthenticated auto-login by default, no credentials are required to reach the vulnerable endpoint, and a single unauthenticated request is sufficient to obtain a valid session token before proceeding with exploitation.
Source: BleepingComputer (Trade Media) · View source
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts