CVE-2026-19306: Langflow is vulnerable to arbitrary local file read due to path traversal in ChatInput, bundle FileInput, and GitExtractor components

Published Aug 28, 2026
·
Updated

IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secretkey, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload directories) — by supplying absolute paths or traversal sequences in the files parameter of an authenticated build request. The file contents were embedded as text attachments in the language model prompt and transmitted to the configured model endpoint, resulting in confidential data exfiltration. This bypassed the LANGFLOWRESTRICTLOCALFILEACCESS=true containment boundary, which was enforced for other file-reading components but not for the Chat Input to Message attachment pipeline.

Other sources

Langflow OSS allows an authenticated attacker to read arbitrary files from the server filesystem — including server secret material (secretkey, JWT signing keys, the application database, /proc/self/environ, and other tenants' upload directories) — by supplying absolute paths or traversal sequences in the files parameter of an authenticated build request. The file contents were embedded as text attachments in the language model prompt and transmitted to the configured model endpoint, resulting in confidential data exfiltration. This bypassed the LANGFLOWRESTRICTLOCALFILEACCESS=true containment boundary, which was enforced for other file-reading components but not for the Chat Input to Message attachment pipeline.

IBM

Affected Software

2 affected components
IBM Langflow>=1.0.0<=1.11.2
IBM Langflow OSS<=1.0.0-1.11.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Langflow OSS to a version that resolves this vulnerability.

    Fixed in 1.11.3
  2. Configuration

    Ensure LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS=true is enforced to contain local file access (noting the boundary was bypassed for the Chat Input to Message attachment pipeline).

    Langflow LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS = true

Event History

Aug 28, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 4, 2026
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
RemedyDescriptionSeverityWeakness

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

Who is exposed to this issue?

IBM Langflow OSS versions 1.0.0 through 1.11.2 are affected. Exploitation requires an authenticated attacker capable of submitting an authenticated build request.

2

Does enabling LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS prevent exploitation?

No. The issue bypasses LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS=true because the restriction was not enforced in the Chat Input to Message attachment pipeline.

3

What can an attacker access if exploitation succeeds?

An attacker can read arbitrary server-local files by supplying absolute paths or traversal sequences in the files parameter. The disclosed data can include secret keys, JWT signing keys, the application database, process environment data, and other tenants' upload directories.

4

How is data exfiltrated through this vulnerability?

Read file contents are embedded as text attachments in the language model prompt and sent to the configured model endpoint. This can expose server data to that endpoint in addition to the authenticated attacker.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203