Improper Pathname Limitation in IBM Langflow OSS Leaving Files Vulnerable
CVE-2026-19303
8.1HIGH
What is CVE-2026-19303?
IBM Langflow OSS versions 1.0.0 through 1.11.2 are susceptible to a vulnerability that allows remote authenticated attackers to delete arbitrary files or directories. This arises from improper limitations placed on pathnames, enabling attackers to perform unauthorized file operations outside the intended directory structure, potentially leading to significant data loss or disruption.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.11.2