CVE-2026-97677: IBM Langflow OSS vulnerability
Published Oct 2, 2026
·Updated
An authenticated flow author could write attacker-controlled file content into any directory writable by the service account, bypassing the platform's local file access isolation safeguard. Via a crafted on-disk index, the attacker could also read the contents of arbitrary files accessible to the service process — including configuration files, secrets, or database files stored under the application's data directory.
Affected Software
1 affected component
IBM Langflow OSS<=1.0.0-1.12.2
Event History
Oct 2, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker must be authenticated and have flow author privileges.
2
Which files and locations could be exposed?
An attacker can write attacker-controlled content to directories writable by the service account and read arbitrary files accessible to the service process. This can include configuration files, secrets, and database files under the application's data directory.