Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
Published: 2026-10-07
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Sensitive information disclosure via improper pathname handling
Action: Update
AI Analysis

Impact

IBM Langflow OSS 1.0.0 through 1.12.2 contains a path‑traversal weakness that allows a remote authenticated attacker to read files outside the intended restricted directory. The flaw arises from insufficient validation of user‑supplied pathnames, enabling disclosure of sensitive configuration or data files. The vulnerability is classified as CWE‑22 and leads to a compromise of confidentiality for data residing beyond the protected folder.

Affected Systems

The affected product is IBM’s Langflow OSS, specifically versions 1.0.0 to 1.12.2. IBM recommends upgrading to 1.12.3 or later to receive the fix that properly limits pathname traversal. Users running earlier releases should immediately plan for the upgrade.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5, indicating a moderate severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, suggesting no current widespread exploitation reports. An attacker must first authenticate to the application, after which they can craft pathnames to read unintended files. Because authentication is required, the attack surface is reduced compared to fully unauthenticated vulnerabilities, but still poses a significant risk if privileged credentials are compromised.

Generated by OpenCVE AI on October 7, 2026 at 01:32 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.12.3. https://pypi.org/project/langflow/#description


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.12.3 or newer to deploy the path‑validation fix.
  • Configure the application to run under the least‑privilege service account, restricting file system access to only the directories that are required.
  • Enable auditing or monitoring of file read operations and review logs for unauthorized path traversal attempts to detect any residual weaknesses.

Generated by OpenCVE AI on October 7, 2026 at 01:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
Title Langflow OSS is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-07T00:02:18.969Z

Reserved: 2026-09-17T22:34:02.340Z

Link: CVE-2026-93448

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T01:16:34.927

Modified: 2026-10-07T01:16:34.927

Link: CVE-2026-93448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T04:15:11Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')