IBM Langflow OSS 1.0.0
IBM Langflow OSS can let an authenticated remote user write files to arbitrary server locations and execute arbitrary code. The impact depends on the permissions available to the server process.
- Severity
- HighCVSS 3.1 · 8.8
- Fix
- Fixed in 1.11.0
- Affected versions
- 1.0.0 through 1.10.3
- Weakness
- CWE-22Path Traversal
- Exploit likelihood
- 0.53% in 30 daysEPSS, higher than 43% of known flaws
- Affects
- Langflow OSS
- Exploited
- Not confirmedNo confirmation recorded
- EU ID
- EUVD-2026-75761ENISA vulnerability database
How it works
- An authenticated attacker abuses Langflow's pathname handling in its file-related features.
- The flaw can let the attacker write content outside the intended storage area.
- A successful attack may overwrite sensitive files, plant malicious content, or corrupt application data, depending on server permissions.
What to do
Check the installed Langflow OSS version and compare it with IBM's advisory. Versions 1.0.0 through 1.10.3 are in scope.
Upgrade Langflow OSS to version 1.11.0, following IBM's security advisory.
Technical details
CVE-2026-84889 is a path traversal flaw in Langflow OSS file handling. IBM rates it high severity with a CVSS score of 8.8 and recommends version 1.11.0.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required Low Attacker needs a basic user account
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- ibm.com · 7286656 vendor-advisory patch NVD
- cve.org · CVERecord vdb entry
- tenable.com · CVE-2026-84889 third party advisory vdb entry
- cvefeed.io · CVE-2026-84889 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-84889