CVE-2026-19299: Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components
Published Aug 28, 2026
·Updated
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal.
Other sources
Langflow OSS could allow a remote authenticated attacker to obtain sensitive information due to path traversal.
— IBM
Affected Software
1 affected component
IBM Langflow OSS<=1.0.0-1.11.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.3 - Configuration
Upgrade Langflow OSS to 1.11.3 to address path traversal that enables arbitrary local file read in ChatInput, the bundle FileInput, and GitExtractor components.
Langflow OSS Path traversal mitigation in ChatInput, FileInput bundle, and GitExtractor = Upgrade to version 1.11.3 (path traversal fix)
Event History
Aug 28, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 4, 2026
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What product should teams check when scoping potentially affected assets?
The affected software is identified as IBM Langflow OSS from IBM.