Impact
IBM Langflow OSS versions 1.0.0 through 1.10.2 contain a path traversal flaw that permits a remote attacker to read arbitrary files on the underlying file system. By forging a URL containing ".." sequences, an attacker can direct the server to traverse directories and access files outside the intended application scope. This results in confidentiality loss, potentially exposing sensitive system files, configuration data, or user credentials.
Affected Systems
The affected product is IBM Langflow OSS. Vulnerable releases include 1.0.0 up to 1.10.2. The CVE notes that the latest available version at the time of disclosure is 1.10.3, which is the recommended upgrade path. No additional vendor or product variants are listed.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. EPSS data is unavailable, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation in the wild yet. The attack vector is inferred to be via HTTP requests, as the flaw is triggered by specially crafted URLs. The attack requires network access to the Langflow OSS instance and the ability to send HTTP GET or POST requests containing path traversal sequences.
OpenCVE Enrichment