Impact
IBM Langflow OSS versions 1.0.0 through 1.11.2 contain a path‑traversal vulnerability that can be triggered through the ChatInput, bundle FileInput, and GitExtractor components. An attacker who has authenticated access within the application can supply a specially crafted input that causes the server to read arbitrary files outside the intended directory. This flaw allows the attacker to obtain sensitive information such as configuration files, secrets, or other data stored on the host system.
Affected Systems
The vulnerability affects the IBM Langflow OSS product, specifically all releases from 1.0.0 up to and including 1.11.2. The exact components that permit the traversal are the ChatInput, bundle FileInput, and GitExtractor features of the framework.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity risk. Because the requirement is remote authenticated access, an attacker must first authenticate to the system before exploiting the flaw, reducing the breadth of potential attackers. EPSS data is not available, so the exploitation likelihood cannot be quantified from that metric, and the vulnerability is not listed in CISA's KEV catalog. The combination of a moderate CVSS, the need for authentication, and the lack of publicly documented exploitation means the risk is medium but should not be neglected.
OpenCVE Enrichment