Impact
IBM Langflow OSS versions 1.0.0 through 1.10.3 allow an attacker to read arbitrary files on the server’s filesystem by sending a crafted MCP resources/read request containing a URL‑encoded path traversal sequence in the filename. The ability to access sensitive files such as JWT signing secrets, SQLite databases, and environment variables results in a confidentiality breach with potential impact on multiple users’ data and system authentication mechanisms.
Affected Systems
The affected product is IBM Langflow OSS. All releases from 1.0.0 up to and including 1.10.3 are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so the exploitation probability is unknown, but path traversal flaws are typically easy to exploit when the vulnerable endpoint is exposed. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, requiring a user who can send an MCP request to the affected system. If the system is exposed, the attacker can read critical files, compromising confidentiality and potentially gaining further footholds. The risk of exploitation is therefore moderate to high for exposed deployments.
OpenCVE Enrichment