Impact
The vulnerability allows a remote attacker to perform directory traversal by sending specially crafted URLs containing "../" sequences to view arbitrary files on the system. This path traversal flaw enables disclosure of sensitive data and may expose configuration files or code artifacts. The weakness is classified as CWE-22 and does not require privilege escalation beyond the application’s process context.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.10.1 are affected. The vulnerability impacts all deployments of these editions that expose any unprotected API endpoint accepting file paths.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity issue. EPSS score of less than 1% indicates a very low exploitation probability. The flaw is exploitable through unauthenticated or insufficiently authorized API endpoints as inferred from the title and typical usage. The vulnerability is not currently listed in CISA KEV, yet the lack of a public exploit does not mitigate the risk of attackers crafting requests to read arbitrary files.
OpenCVE Enrichment