CVE-2026-84889: A path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitrary locations on the server filesystem
Published Sep 8, 2026
·Updated
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
Other sources
Langflow OSS could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
— IBM
Affected Software
1 affected component
IBM Langflow OSS<=1.0.0-1.10.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Sep 8, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Sep 10, 2026
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments require remediation?
IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected.
2
Does exploitation require prior access?
Yes. An attacker must be authenticated, but exploitation can be performed remotely over the network without user interaction.