Skip to content
IBMCVE-2026-7658

IBM Langflow OSS: path traversal

Medium6.5CVE-2026-7658 · Published Aug 5, 2026 · updated Aug 6, 2026

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key deletion leading to session invalidation.

IBM advisory

Affected versions

PackageAffectedFixed in
Langflow OSS
Product
>= 1.0.0, <= 1.10.3No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-22

More IBM advisories

All IBM
Advisory
IBM Langflow OSS: weak cryptography
High7.4Aug 5
IBM Langflow OSS: code injection
High8.1Aug 5
IBM Langflow OSS: code execution
High8.8Aug 5
IBM Langflow OSS: information disclosure
High7.1Aug 5
IBM Langflow OSS: code injection
High8.8Aug 5
IBM Langflow OSS: broken cryptography
High7.4Aug 5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.