CVE report

CVE-2026-5027high

Langflow <= 1.8.4 - Path Traversal to RCE via File Upload

Events 90d

479

Distinct IPs

40

Severity

high

CISA KEV

Not listed

Detection signature

An event counts toward CVE-2026-5027 when its URL path contains any of these (case-insensitive). This is what our matching is based on.

  • · /api/v1/login
  • · /api/v2/files
  • · /api/v1/auto_login

Pre-disclosure activity

all early actors →

Analysing probe history around the publication date…

Recent probe volume (last 7 days)

peak: 154 events/day
05-1105-2906-2006-2607-0207-1107-27
eventsdistinct IPs

Downloads & integrations

Top sources probing for CVE-2026-5027

Top networks the attempts come from

Fingerprints of the clients exploiting this

The HTTP (JA4H) and TLS (JA4) fingerprints seen on these attempts. Click one to see the whole population that carries it.

Sample request paths observed

  • /api/v2/files.rar
  • /api/v2/files.tar.gz
  • /api/v2/files.tgz
  • /api/v2/files.tar
  • /api/v2/files.tar.bz2
  • /api/v2/files.zip
  • /api/v2/files.tar.xz
  • /api/v1/auto_login
  • /api/v2/files.gz
  • /api/v2/files.7z