IBM Langflow OSS: insecure direct object reference
High8.1CVE-2026-13445 · Published Jul 17, 2026 · updated Jul 23, 2026
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's workflow reads victim file contents, appends attacker-controlled data, and uploads a copy containing victim data to the attacker's namespace (confidentiality breach). In overwrite mode, the attacker can replace victim file contents with arbitrary data (integrity breach). This breaks the storage ownership boundary between users.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Langflow OSS Product | >= 1.0.0, <= 1.10.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-639
More IBM advisories
All IBM| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 17 | IBM Langflow OSS: hard-coded credentials | Critical9.8 | No fix yet |
| Jul 17 | IBM Langflow OSS: remote code execution | Critical9.8 | No fix yet |
| Jul 17 | IBM Langflow OSS: privilege escalation | Critical9.9 | No fix yet |
| Jul 17 | IBM Langflow OSS: improper input validation | Critical9.9 | No fix yet |
| Jul 17 | IBM Security Verify Access: information disclosure | Medium5.3 | No fix yet |
| Jul 17 | IBM Langflow OSS: remote code execution | High8.8 | No fix yet |