Path Traversal Vulnerability in Langflow Tool by Langflow AI
CVE-2025-68478
What is CVE-2025-68478?
The Langflow tool, developed by Langflow AI, is subject to a path traversal vulnerability where an attacker can specify an arbitrary path in the fs_path parameter of the request body. This flaw enables unauthorized access and manipulation of server files by allowing the creation or overwriting of files without directory restrictions. Prior to version 1.7.0, the software failed to normalize or enforce allowed directories, permitting the execution of absolute paths such as /etc/poc.txt. Version 1.7.0 addresses this issue by implementing necessary restrictions to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
langflow < 1.7.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
