PT-2026-68291 · Ibm · Langflow Oss
CVE-2026-7869
·
Published
2026-08-05
·
Updated
2026-08-06
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Langflow OSS versions 1.0.0 through 1.10.3
Description
An authenticated attacker can perform a Path Traversal attack via the Knowledge Bases API endpoint
POST /api/v1/knowledge bases. This issue arises because the system uses user-supplied knowledge base names to create file paths without proper sanitization or containment checks, allowing the creation of directories and the writing of files anywhere on the server filesystem.Recommendations
Update IBM Langflow OSS to a version later than 1.10.3.
Restrict the use of the
POST /api/v1/knowledge bases endpoint until the update is applied.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langflow Oss