Impact
The vulnerability allows an attacker to include ".." sequences in a URL, enabling them to traverse directories and view arbitrary files on the system. This path traversal flaw can expose sensitive configuration files or data that may be leveraged for further compromise. The flaw exists in the custom component validation and trusted code enforcement logic of IBM Langflow OSS.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected. Any deployment using these releases is susceptible until a patch is applied.
Risk and Exploitability
The CVSS score of 7.7 reflects considerable risk. Although no EPSS data is available, the flaw is remotely exploitable via crafted HTTP requests without authentication or prior access. It is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment