Impact
The vulnerability is a path traversal flaw (CWE-22) that allows a remote authenticated attacker to read sensitive files on the server. By supplying crafted file paths, the attacker can access files outside the intended directory, leading to the disclosure of confidential data. This flaw does not provide direct code execution but can expose credentials, configuration files, or other sensitive information stored on the server.
Affected Systems
The affected vendor is IBM. The product is Langflow OSS, with vulnerable releases ranging from 1.0.0 through 1.12.2. IBM recommends upgrading to version 1.12.3 or later to remediate the issue.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. Because the flaw requires the attacker to be authenticated to the system, the attack vector is remote with valid credentials, and the EPSS score is not available, the exploitation likelihood is uncertain but potentially significant in environments where credentials are widely distributed. The vulnerability is not listed in the CISA KEV catalog. Mitigation is straightforward: apply the vendor patch when available, otherwise employ input validation or access restriction as a workaround.
OpenCVE Enrichment