Description
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write
Action: Patch Immediately
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.10.3 contain a path traversal flaw caused by inadequate pathname restriction in the file handling component. An attacker who is authenticated can supply specially crafted file paths that resolve outside the intended upload directory, enabling the creation or overwriting of arbitrary files. This weakness is a classic instance of CWE‑22 and can lead to remote code execution if the attacker writes executable files to a location with execution permissions.

Affected Systems

IBM Langflow OSS, version 1.0.0 up to 1.10.3, is used on servers hosting the open‑source workflow tool. Systems running these versions are affected by the path traversal issue and may allow authenticated users to upload or modify files on the server filesystem.

Risk and Exploitability

The CVSS score of 8.8 classifies this vulnerability as high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authentication, the risk is limited to users with valid credentials, but once authenticated the attacker can write files to arbitrary locations, potentially enabling malicious code execution. The lack of a public exploit and the need for authentication reduce the likelihood of exploitation compared to unauthenticated flaws, yet the potential impact remains significant for any environment that accepts authenticated file uploads.

Generated by OpenCVE AI on September 11, 2026 at 05:09 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.0 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.11.0 as IBM recommends.
  • If an upgrade is not immediately possible, configure the upload handling to restrict writes to a dedicated directory and sanitize all file paths to eliminate traversal sequences.
  • Ensure that the designated upload directory has minimal executable permissions, and monitor upload logs for unexpected file paths or modifications.

Generated by OpenCVE AI on September 11, 2026 at 05:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Langflow
Langflow langflow
CPEs cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Vendors & Products Langflow
Langflow langflow

Sat, 12 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
Title A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitrary locations on the server filesystem
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.10.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
Langflow Langflow
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-12T15:36:04.812Z

Reserved: 2026-09-02T14:32:32.245Z

Link: CVE-2026-84889

cve-icon Vulnrichment

Updated: 2026-09-12T15:32:48.565Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:04.347

Modified: 2026-09-14T20:11:04.947

Link: CVE-2026-84889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T09:00:10Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')