Skip to content
IBMCVE-2026-9225

IBM Langflow OSS: improper access control

Medium6.5CVE-2026-9225 · Published Sep 10, 2026 · updated Sep 15, 2026

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api/v1/run/advanced/{flow_id} endpoint, the application allows component inputs to reference storage paths using arbitrary user or flow identifiers without verifying ownership. An attacker with low‑privileged authenticated access can supply a crafted file path pointing to another user’s storage namespace, causing the backend to read and return the contents of files uploaded by other users. This vulnerability bypasses intended authorization checks enforced by the file management API and may result in unauthorized disclosure of sensitive user data.

IBM advisory

Affected versions

PackageAffectedFixed in
Langflow OSS
Product
>= 1.0.0, <= 1.11.5No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-639

More IBM advisories

All IBM
Advisory
IBM DataStage on Cloud Pak for Data: denial of service
Critical9.6Sep 10
IBM DataStage on Cloud Pak for Data: information disclosure
Critical9.6Sep 10
IBM Langflow OSS: remote code execution
High8.8Sep 10
IBM Db2: path traversal
Medium4.3Sep 10
IBM Db2: code execution
High7.5Sep 10
IBM Db2: denial of service
High8.1Sep 10

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.