CVE-2026-19302: Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components
Published Aug 28, 2026
·Updated
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
Other sources
Langflow OSS could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
— IBM
Affected Software
1 affected component
IBM Langflow OSS<=1.0.0-1.11.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.3 - Compensating control
Limit remote authenticated access to Langflow OSS so only trusted users/networks can reach the affected endpoints/components (ChatInput, bundle FileInput, GitExtractor) until the upgrade to 1.11.3 is completed.
Event History
Aug 28, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 4, 2026
CVE Published
via MITRE·03:41 PM
Data Sourced
via MITRE·03:41 PM
RemedyDescriptionSeverityWeakness