CVE-2026-97671: Langflow OSS is affected by multiple vulnerabilities
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.
Other sources
Langflow OSS could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.12.3
Event History
Frequently Asked Questions
Does exploitation require authentication or user interaction?
An attacker must be authenticated and able to reach the affected instance over the network. No user interaction is required, and the attack complexity is rated low.
What is the expected security impact?
Successful exploitation can expose sensitive information through path traversal. The supplied severity vector indicates a high confidentiality impact, with no stated integrity or availability impact.
Which releases are identified as affected?
IBM Langflow OSS versions 1.0.0 through 1.12.2 are identified as affected.