CVE-2026-8183: Langflow OSS is affected by arbitrary code execution in custom component validation and trusted code enforcement
IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to v i ew arbitrary files on the system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8183?
The severity of CVE-2026-8183 is rated as high with a score of 7.7.
How do I fix CVE-2026-8183?
To fix CVE-2026-8183, upgrade IBM Langflow OSS to a version higher than 1.10.3.
What kind of vulnerability is CVE-2026-8183?
CVE-2026-8183 is a vulnerability related to arbitrary code execution due to improper validation in custom components.
What systems are affected by CVE-2026-8183?
IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected by CVE-2026-8183.
What is the risk associated with CVE-2026-8183?
The risk associated with CVE-2026-8183 includes potential directory traversal by a remote attacker.