CVE-2026-19303: Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.
Other sources
Langflow OSS could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.3 - Compensating control
If immediate upgrade to Langflow OSS 1.11.3 is not possible, restrict network access to the Langflow service so only trusted clients/users can authenticate and reach the affected file-processing functionality.
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue requires remote authenticated access to IBM Langflow OSS.
What is the potential impact of successful exploitation?
An authenticated remote attacker could delete arbitrary local files or directories because pathname handling is not properly restricted to an intended directory.