ClosedMedium impactAI Refreshed

Path traversal vulnerability in Langflow AI platform actively exploited

Occurred 10 Jun 2026·Detected 16 Jun 2026·
Global - vulnerability affects publicly exposed Langflow instances worldwide2 reportsEnded 28 Jun 2026
CyberPropertyCyberCasualty & Liability

CVE-2026-5027, a high-severity unauthenticated path traversal vulnerability in the Langflow AI development platform, is being actively exploited. A patch is available in Langflow 1.10.0. Censys identified roughly 7,000 publicly exposed Langflow instances, though the figure may include historical data. Exploitation evidence to date is limited to test-file drops on VulnCheck honeypots; no insured losses, breach notifications, or claims activity have been confirmed. Materiality depends on patch adoption rates and whether exploitation progresses beyond initial access.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Medium impact. Loss pathway is cyber. Unauthenticated exploitation of a widely deployed AI development platform, combined with default unauthenticated auto-login and a history of prior Langflow CVEs being exploited (including a CISA-noted link to the Iranian state-sponsored group MuddyWater), raises the ceiling of potential accumulation risk. Counterweights: no confirmed insured losses, breach notifications, or claims activity, and exploitation evidence to date is limited to test file drops detected in honeypots. Materiality depends on patch adoption rates among the exposed footprint and whether exploitation progresses beyond initial access. Relevant to cyber underwriters monitoring accumulation risk across AI/tech insureds and to incident-response capacity planning.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts