Path traversal vulnerability in Langflow AI platform actively exploited
CVE-2026-5027, a high-severity unauthenticated path traversal vulnerability in the Langflow AI development platform, is being actively exploited. A patch is available in Langflow 1.10.0. Censys identified roughly 7,000 publicly exposed Langflow instances, though the figure may include historical data. Exploitation evidence to date is limited to test-file drops on VulnCheck honeypots; no insured losses, breach notifications, or claims activity have been confirmed. Materiality depends on patch adoption rates and whether exploitation progresses beyond initial access.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Medium impact. Loss pathway is cyber. Unauthenticated exploitation of a widely deployed AI development platform, combined with default unauthenticated auto-login and a history of prior Langflow CVEs being exploited (including a CISA-noted link to the Iranian state-sponsored group MuddyWater), raises the ceiling of potential accumulation risk. Counterweights: no confirmed insured losses, breach notifications, or claims activity, and exploitation evidence to date is limited to test file drops detected in honeypots. Materiality depends on patch adoption rates among the exposed footprint and whether exploitation progresses beyond initial access. Relevant to cyber underwriters monitoring accumulation risk across AI/tech insureds and to incident-response capacity planning.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialLloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts