Impact
The vulnerability arises from improper limitation of a file pathname, allowing a remote authenticated attacker to perform path traversal and read arbitrary files. In plaintext, the attack enables access to files outside the intended directory, potentially exposing sensitive configuration or user data. This is a classic information disclosure flaw mapped to CWE-22.
Affected Systems
IBM Langflow OSS versions between 1.0.0 and 1.10.2 are affected. The vulnerability has been identified in the file and knowledge base components of the application and is present in the main package distribution used by customers.
Risk and Exploitability
The CVSS score of 6.5 signals a moderate severity, and there is no EPSS data available. The vulnerability is not in the CISA KEV catalog. An attacker must first authenticate to the system; once authenticated, the path traversal can be exploited to read files from the underlying operating system. Because the flaw is purely informational, the impact is restricted to data disclosure rather than execution or denial of service.
OpenCVE Enrichment