Path Traversal Vulnerability in Langflow Tool by Langflow AI
CVE-2025-68478
7.1HIGH
What is CVE-2025-68478?
The Langflow tool, developed by Langflow AI, is subject to a path traversal vulnerability where an attacker can specify an arbitrary path in the fs_path parameter of the request body. This flaw enables unauthorized access and manipulation of server files by allowing the creation or overwriting of files without directory restrictions. Prior to version 1.7.0, the software failed to normalize or enforce allowed directories, permitting the execution of absolute paths such as /etc/poc.txt. Version 1.7.0 addresses this issue by implementing necessary restrictions to prevent exploitation.
Affected Version(s)
langflow < 1.7.0
