CVE-2026-7658: Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key deletion leading to session invalidation.
Other sources
Langflow OSS does not properly validate the
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0 - Compensating control
After upgrading, ensure any affected tenant/custom component validation and trusted code enforcement controls are re-verified to prevent abuse of custom component validation and trusted code enforcement weaknesses described for Langflow OSS.
- Operational
If JWT signing key deletion/session invalidation may have occurred, rotate any JWT signing keys/secrets to restore session validity after remediation.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7658?
CVE-2026-7658 has a medium severity rating of 6.5.
What impacts are associated with CVE-2026-7658?
CVE-2026-7658 can lead to arbitrary directory deletion, cross-tenant data destruction, and JWT signing key compromise.
How do I fix CVE-2026-7658?
To mitigate CVE-2026-7658, ensure that the username field is properly validated to prevent path traversal injections.
What products are affected by CVE-2026-7658?
CVE-2026-7658 affects IBM Langflow OSS versions 1.0.0 through 1.10.3.
Is CVE-2026-7658 a type of path traversal vulnerability?
Yes, CVE-2026-7658 is categorized under path traversal vulnerabilities.