CVE-2026-19302: Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components
Published Aug 28, 2026
·Updated
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
Other sources
Langflow OSS could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
— IBM
Affected Software
5 affected components
IBM Langflow OSS<=1.0.0-1.11.2
All of the following
Langflow Langflow>=1.0.0<1.11.3
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.3
Event History
Aug 28, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 4, 2026
CVE Published
via MITRE·03:41 PM
Data Sourced
via MITRE·03:41 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
RemedyDescriptionSeverityWeaknessAffected Software