Description
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.
Published: 2026-09-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized file system access
Action: Patch Upgrade
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a path traversal flaw and missing storage path validation that lets a remote authenticated attacker read arbitrary files. The weakness enables disclosure of any file the attacker can access through the filesystem, undermining confidentiality for the affected system

Affected Systems

The vulnerability affects IBM Langflow OSS 1.0.0 through 1.11.5. Users of any of these releases are at risk if they allow authenticated access to the feature that processes file paths without verifying the target directory

Risk and Exploitability

The CVSS score of 6.5 categorizes the issue as moderate. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. An attacker must be authenticated to exploit it the necessary access. With valid credentials and the ability to craft a request containing a traversal sequence, the attacker can read any file accessible to the application’s process, potentially exposing sensitive system data.

Generated by OpenCVE AI on September 11, 2026 at 04:45 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.6 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.11.6 to address the path traversal vulnerability
  • Apply strict input validation for file path parameters and enforce a whitelist of allowed directories to block traversal attempts
  • If upgrading is not immediate, restrict access to the vulnerable feature to privileged users only or disable it, and isolate the application within a container with limited filesystem permissions

Generated by OpenCVE AI on September 11, 2026 at 04:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.
Title Langflow is vulnerable to unauthorized file system access due to path traversal and missing storage path validation
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-284
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T21:40:06.590Z

Reserved: 2026-08-25T13:58:15.687Z

Link: CVE-2026-79725

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T22:17:00.657

Modified: 2026-09-10T22:17:00.657

Link: CVE-2026-79725

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T07:15:16Z

Weaknesses