ZeroHour

CVE-2026-18899

moderate

Arbitrary File Read via Path Traversal in IBM Langflow OSS

CVSS 3.1
7.5 high
EPSS
<1%p39
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a path traversal flaw (CWE-22) that allows a remote attacker to read arbitrary files from the host running the application. The flaw is triggered by sending crafted network requests containing traversal sequences that bypass intended directory restrictions, requiring no authentication or user interaction. A successful attacker gains read access to sensitive files on the server, such as configuration files, credentials, or environment data; per the CVSS score, there is no impact on integrity or availability. Anyone running an affected Langflow OSS release is impacted, with internet-exposed instances facing the greatest risk. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days.

What to do: Upgrade Langflow OSS to a fixed release newer than 1.11.1 as published by IBM/psirt. Until patched, restrict network access to Langflow instances and avoid exposing them directly to the internet; verify externally reachable instances via asset inventories or scans. Monitor vendor advisories for a specific fixed version and watch for public PoCs, as active exploitation has not yet been reported.

Affected
IBM Langflow OSS1.0.0 through 1.11.1
Estimated exposure
moderatelikely on the order of thousands of deployed instances (no authoritative install base count; the internet-exposed subset is probably smaller, as many… — Langflow is a widely used open-source AI agent/workflow builder typically self-hosted by developers and teams, but no public scan or install-count data is available in this record, so the estimate is based on deployment patterns rather…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.

Vendors
langflow
Products
langflow
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.