CVE-2026-14470: Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components
IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Other sources
Langflow could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.3 - Compensating control
Because Langflow OSS could allow an authenticated attacker to traverse directories and read arbitrary files via path traversal, restrict access to Langflow OSS to trusted users only (e.g., enforce strong authentication and limit who can authenticate to the application).
Event History
Frequently Asked Questions
Which product is identified as affected?
The affected software is IBM Langflow OSS from IBM.
Does exploitation require prior access?
Yes. The issue is described as requiring an authenticated attacker.