Impact
IBM Langflow OSS 1.0.0 through 1.12.2 contains a path‑traversal weakness that allows a remote authenticated attacker to read files outside the intended restricted directory. The flaw arises from insufficient validation of user‑supplied pathnames, enabling disclosure of sensitive configuration or data files. The vulnerability is classified as CWE‑22 and leads to a compromise of confidentiality for data residing beyond the protected folder.
Affected Systems
The affected product is IBM’s Langflow OSS, specifically versions 1.0.0 to 1.12.2. IBM recommends upgrading to 1.12.3 or later to receive the fix that properly limits pathname traversal. Users running earlier releases should immediately plan for the upgrade.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating a moderate severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, suggesting no current widespread exploitation reports. An attacker must first authenticate to the application, after which they can craft pathnames to read unintended files. Because authentication is required, the attack surface is reduced compared to fully unauthenticated vulnerabilities, but still poses a significant risk if privileged credentials are compromised.
OpenCVE Enrichment