CVE-2026-93448: Langflow OSS is affected by multiple vulnerabilities
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
Other sources
Langflow OSS could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.12.3
Event History
Frequently Asked Questions
Who can exploit this issue?
A remote attacker must be authenticated and have at least low-level privileges. The issue is network-accessible and does not require user interaction.
What is the impact of successful exploitation?
An attacker could obtain sensitive information by accessing pathnames outside the intended restricted directory. The provided impact vector indicates confidentiality impact only; integrity and availability are not affected.
Which versions are affected?
IBM Langflow OSS versions 1.0.0 through 1.12.2 are identified as affected.