CVE-2026-7524: Path Traversal Vulnerability in File Processing Components Allows Unauthorized File System Access and Potential Remote Code Execution
Published May 19, 2026
·Updated
IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.
Other sources
Langflow OSS could allow remote code execution due to improper validation of symbolic links during archive extraction.
— IBM
Affected Software
2 affected components
IBM Langflow OSS<=1.0.0-1.9.1
Langflow Langflow>=1.0.0<=1.9.1
Remediation
Information
IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.9.2 https://pypi.org/project/langflow/ .
Event History
May 19, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
May 27, 2026
CVE Published
via MITRE·01:14 PM
Data Sourced
via MITRE·01:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-7524?
CVE-2026-7524 has a critical severity rating of 9.8.
2
What does CVE-2026-7524 exploit?
CVE-2026-7524 exploits improper validation of symbolic links during archive extraction.
3
How do I fix CVE-2026-7524?
To fix CVE-2026-7524, upgrade Langflow OSS to version 1.9.2.
4
What are the potential impacts of CVE-2026-7524?
CVE-2026-7524 could lead to unauthorized file system access and remote code execution.
5
Which versions of Langflow OSS are affected by CVE-2026-7524?
CVE-2026-7524 affects versions 1.0.0 through 1.9.1 of Langflow OSS.