Impact
IBM Langflow OSS 1.0.0 through 1.11.2 contains a path traversal flaw in the ChatInput, bundle FileInput, and GitExtractor components that allows a remote authenticated attacker to read arbitrary files from the file system. The vulnerability stems from improper validation of symbolic links during file handling, enabling an attacker to craft an input that resolves to locations outside the intended directory. Successful exploitation could expose sensitive configuration files, credentials, or other confidential data, compromising confidentiality and potentially leading to further system compromise.
Affected Systems
The affected product is IBM Langflow OSS, versions from 1.0.0 up to and including 1.11.2. The vendor explicitly recommends upgrading to version 1.11.3 to resolve this issue.
Risk and Exploitability
The base CVSS score of 6.5 indicates a moderate severity vulnerability. EPSS data is not available, and the issue is not currently listed in CISA’s KEV catalog. The flaw requires the attacker to be authenticated with the application, but once authenticated, the attacker can submit crafted input to trigger the traversal. This makes it an enterprise‑level concern for systems that expose the vulnerable components to network or cloud environments, as the impact includes potential leakage of confidential data. Given the moderate CVSS rating, the risk is significant enough that remediation should occur as soon as possible, but the lack of public exploit evidence currently reduces the urgency compared to high‑CVSS flaws.
OpenCVE Enrichment