Description
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
Published: 2026-09-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Local File Read
Action: Patch Now
AI Analysis

Impact

IBM Langflow OSS 1.0.0 through 1.11.2 contains a path traversal flaw in the ChatInput, bundle FileInput, and GitExtractor components that allows a remote authenticated attacker to read arbitrary files from the file system. The vulnerability stems from improper validation of symbolic links during file handling, enabling an attacker to craft an input that resolves to locations outside the intended directory. Successful exploitation could expose sensitive configuration files, credentials, or other confidential data, compromising confidentiality and potentially leading to further system compromise.

Affected Systems

The affected product is IBM Langflow OSS, versions from 1.0.0 up to and including 1.11.2. The vendor explicitly recommends upgrading to version 1.11.3 to resolve this issue.

Risk and Exploitability

The base CVSS score of 6.5 indicates a moderate severity vulnerability. EPSS data is not available, and the issue is not currently listed in CISA’s KEV catalog. The flaw requires the attacker to be authenticated with the application, but once authenticated, the attacker can submit crafted input to trigger the traversal. This makes it an enterprise‑level concern for systems that expose the vulnerable components to network or cloud environments, as the impact includes potential leakage of confidential data. Given the moderate CVSS rating, the risk is significant enough that remediation should occur as soon as possible, but the lack of public exploit evidence currently reduces the urgency compared to high‑CVSS flaws.

Generated by OpenCVE AI on September 4, 2026 at 20:59 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.3 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.11.3 as recommended by IBM.
  • If an immediate upgrade is not feasible, restrict or disable the vulnerable ChatInput, bundle FileInput, and GitExtractor components until a patch can be applied.
  • Enforce strict validation of file paths at the application layer and monitor for unauthorized file access attempts to detect and contain potential exploitation.

Generated by OpenCVE AI on September 4, 2026 at 20:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Langflow
Langflow langflow
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Langflow
Langflow langflow
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 04 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
Title Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Apple Macos
Ibm Langflow Oss
Langflow Langflow
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T18:24:51.065Z

Reserved: 2026-08-07T17:24:12.727Z

Link: CVE-2026-19302

cve-icon Vulnrichment

Updated: 2026-09-04T17:39:57.979Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T16:17:23.960

Modified: 2026-09-08T22:13:42.027

Link: CVE-2026-19302

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T23:00:15Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')