Threats
Langflow Path Traversal CVE-2026-5027 Actively Exploited; Default Auto-Login Hands Attackers Unauthenticated File Write
Attackers are actively exploiting CVE-2026-5027 in Langflow, writing arbitrary files to exposed servers. Default unauthenticated auto-login means a single request reaches the vulnerable endpoint with no credentials. Roughly 7,000 instances were exposed; patch in 1.10.0.