CVE-2026-17621: Langflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base components
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.3
Event History
Frequently Asked Questions
Does an attacker need an account to exploit this issue?
The CVSS vector lists Privileges Required as Low, indicating the attacker needs low-level privileges. No user interaction is required.
Which systems should be assessed first?
Assess IBM Langflow OSS installations running versions 1.0.0 through 1.10.2, particularly those reachable remotely. The reported impact is disclosure of arbitrary files through crafted requests containing directory-traversal sequences.