Langflow APIRequest Component Path Traversal via Content-Disposition Header
criticalAgentFramework VulnerabilityLangflow's APIRequest component, when its 'Save to File' feature is enabled, trusts filenames supplied by an external HTTP server's Content-Disposition header without sanitizing them. A malicious or compromised remote endpoint can inject path traversal sequences to write arbitrary files outside the intended temporary directory, potentially leading to full remote code execution on the host running the agent flow.
Updated Jul 20, 2026 · CVSS 9.9