CVE-2026-42048 is a path traversal vulnerability in Langflow, a tool for building and deploying AI-powered agents and workflows. The issue affects versions prior to 1.9.0 and is present in the Knowledge Bases API DELETE endpoint at /api/v1/knowledge_bases. The flaw occurs because user-supplied knowledge base names are concatenated directly into filesystem paths without proper sanitization or boundary validation. As a result, an authenticated attacker can supply traversal sequences or otherwise crafted path input to cause the application to operate on directories outside the intended knowledge base storage location. In the described exploitation path, this allows arbitrary directory deletion anywhere on the server filesystem.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained lab and proof-of-concept for CVE-2026-42048, a Langflow path traversal / arbitrary directory deletion vulnerability affecting versions before 1.9.0. The repo contains 6 files: a Dockerfile that builds a vulnerable Langflow 1.8.4 environment, a shell entrypoint that initializes the lab and launches Langflow plus a proxy, a Python challenge proxy that hides the full backend and exposes only minimal routes, a Python PoC exploit script, a README with vulnerability details and usage, and a fake flag file. The main exploit capability is arbitrary directory deletion via the vulnerable DELETE /api/v1/knowledge_bases endpoint. The PoC in poc.py sends a JSON body with kb_names containing an absolute filesystem path, defaulting to /target/CVE-2026-42048. Because vulnerable Langflow joins attacker-controlled kb_names into a filesystem path without proper normalization and containment checks, an absolute path or traversal sequence can escape the intended per-user knowledge base directory and trigger recursive deletion of an arbitrary directory that the Langflow process can remove. challenge-proxy.py is central to the lab design. It listens on 0.0.0.0:9101, authenticates to the internal Langflow instance at http://127.0.0.1:7860 using configured superuser credentials, prepares the user KB directory, and forwards DELETE requests to /api/v1/knowledge_bases with a bearer token. It also exposes /health, /status, /, and /flag.txt. This means the public-facing lab endpoint does not require the user to handle authentication directly; the proxy performs that step and forwards the exploit request to the vulnerable backend. The exploit is operational rather than just demonstrative because it performs the full attack flow against the lab target and produces a concrete effect: deletion of the target directory. It is not weaponized in the framework sense, and it does not deliver code execution; its impact is integrity/availability through filesystem deletion. The repository is a real exploit lab, not merely a detector or README-only advisory.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.