Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.
Published: 2026-10-07
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Remote Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a path traversal flaw (CWE-22) that allows a remote authenticated attacker to read sensitive files on the server. By supplying crafted file paths, the attacker can access files outside the intended directory, leading to the disclosure of confidential data. This flaw does not provide direct code execution but can expose credentials, configuration files, or other sensitive information stored on the server.

Affected Systems

The affected vendor is IBM. The product is Langflow OSS, with vulnerable releases ranging from 1.0.0 through 1.12.2. IBM recommends upgrading to version 1.12.3 or later to remediate the issue.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. Because the flaw requires the attacker to be authenticated to the system, the attack vector is remote with valid credentials, and the EPSS score is not available, the exploitation likelihood is uncertain but potentially significant in environments where credentials are widely distributed. The vulnerability is not listed in the CISA KEV catalog. Mitigation is straightforward: apply the vendor patch when available, otherwise employ input validation or access restriction as a workaround.

Generated by OpenCVE AI on October 7, 2026 at 01:37 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.12.3. https://pypi.org/project/langflow/#description


OpenCVE Recommended Actions

  • Upgrade Langflow OSS to version 1.12.3 or later.
  • If upgrade is not immediately feasible, limit authenticated access to the application and enforce strict path validation to prevent traversal exploits.
  • As a temporary measure, remove or sanitize any API endpoints that allow arbitrary file path specification or reject paths containing relative components such as "..".

Generated by OpenCVE AI on October 7, 2026 at 01:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.
Title Langflow OSS is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.12.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-10-07T00:00:26.358Z

Reserved: 2026-09-24T20:33:21.573Z

Link: CVE-2026-97671

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T01:16:35.980

Modified: 2026-10-07T01:16:35.980

Link: CVE-2026-97671

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:45:08Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')