CVE-2026-7658

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key deletion leading to session invalidation.
References
Link Resource
https://www.ibm.com/support/pages/node/7282647 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-05 19:17

Updated : 2026-08-06 19:01


NVD link : CVE-2026-7658

Mitre link : CVE-2026-7658

CVE.ORG link : CVE-2026-7658


JSON object : View

Products Affected

langflow

  • langflow
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')