Impact
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to insert path‑traversal sequences that bypass containment checks. This flaw can be used to delete arbitrary directories, including cross‑tenant data and the JWT signing key, which in turn invalidates user sessions and erases data. The vulnerability is a form of path‑traversal (CWE‑22) that leads to significant data loss and service disruption.
Affected Systems
The affected products are IBM’s Langflow OSS, specifically all releases from version 1.0.0 up to and including 1.10.3. The vulnerability is tied to the version range 1.0.0–1.10.3 and no later releases beyond 1.10.3 are impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. An attacker can reach this flaw through the web interface by supplying a malicious username; this likely requires authenticated or unauthenticated access to the login form or related API. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the overall exploitation probability is unknown, but the potential for data destruction warrants careful attention.
OpenCVE Enrichment