CVE-2026-12942: Langflow is affected by path traversal due to multiple unauthenticated and insufficiently authorized API endpoints
IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.2 - Compensating control
Because multiple unauthenticated and insufficiently authorized API endpoints are implicated in path traversal, restrict access to Langflow OSS API endpoints to authenticated/authorized clients until the upgrade to 1.10.2 is completed.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12942?
The severity of CVE-2026-12942 is rated as high with a score of 7.5.
What type of vulnerability is CVE-2026-12942?
CVE-2026-12942 is classified as a path traversal vulnerability.
How can an attacker exploit CVE-2026-12942?
An attacker can exploit CVE-2026-12942 by sending a specially crafted URL request with 'dot dot' sequences to traverse directories.
What versions of Langflow are affected by CVE-2026-12942?
CVE-2026-12942 affects IBM Langflow OSS versions 1.0.0 through 1.10.1.
How do I remediate CVE-2026-12942?
To remediate CVE-2026-12942, ensure that your Langflow installation is updated to a version that has patched the vulnerability.