Impact
IBM Langflow OSS versions 1.0.0 through 1.10.3 contain a path traversal flaw caused by inadequate pathname restriction in the file handling component. An attacker who is authenticated can supply specially crafted file paths that resolve outside the intended upload directory, enabling the creation or overwriting of arbitrary files. This weakness is a classic instance of CWE‑22 and can lead to remote code execution if the attacker writes executable files to a location with execution permissions.
Affected Systems
IBM Langflow OSS, version 1.0.0 up to 1.10.3, is used on servers hosting the open‑source workflow tool. Systems running these versions are affected by the path traversal issue and may allow authenticated users to upload or modify files on the server filesystem.
Risk and Exploitability
The CVSS score of 8.8 classifies this vulnerability as high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authentication, the risk is limited to users with valid credentials, but once authenticated the attacker can write files to arbitrary locations, potentially enabling malicious code execution. The lack of a public exploit and the need for authentication reduce the likelihood of exploitation compared to unauthenticated flaws, yet the potential impact remains significant for any environment that accepts authenticated file uploads.
OpenCVE Enrichment