CVE-2026-14470: Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components
Published Sep 3, 2026
·Updated
IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Other sources
Langflow could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
— IBM
Affected Software
1 affected component
IBM Langflow OSS<=1.0.0-1.10.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.3
Event History
Sep 3, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 4, 2026
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which product is identified as affected?
The affected software is IBM Langflow OSS from IBM.
2
Does exploitation require prior access?
Yes. The issue is described as requiring an authenticated attacker.