ZeroHour

CVE-2026-84889

large

Authenticated path traversal RCE in IBM Langflow OSS 1.0.0-1.10.3

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.10.3 contain a path-traversal flaw (CWE-22): the application fails to properly limit a user-supplied pathname to a restricted directory, so a crafted path can escape the intended folder. A remote attacker who holds valid low-privilege credentials can send an authenticated request with such a crafted pathname over the network, and successful exploitation results in arbitrary code execution on the host running Langflow, with high impact on confidentiality, integrity, and availability (CVSS 3.1 base score 8.8). Because exploitation requires an authenticated account, instances with open or loosely controlled user access face the greatest risk, while strictly internal deployments with few trusted users are less exposed. Anyone running Langflow OSS within the affected version range should plan remediation; the CVE was assigned by IBM's PSIRT. As of this writing there is no known public proof-of-concept, the issue is not listed in CISA's Known Exploited Vulnerabilities catalog, and no in-the-wild exploitation has been confirmed.

What to do: Upgrade Langflow to a release newer than 1.10.3 as soon as a fixed version is published and verify the deployed version afterward. Until then, limit Langflow accounts to trusted users, run the service under a least-privilege account, and restrict network exposure to trusted networks. Review logs for authenticated requests containing unusual or dot-dot file paths and for unexpected process execution on the Langflow host.

Affected
IBM Langflow OSS1.0.0 through 1.10.3
Estimated exposure
largelikely tens of thousands of self-hosted instances (exact install counts untracked) — Langflow is a widely adopted open-source AI agent/workflow builder typically self-hosted via pip or Docker without public install telemetry, so this is an order-of-magnitude estimate from adoption and deployment patterns rather than a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

Vendors
langflow
Products
langflow
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.