File Access Vulnerability in IBM Langflow OSS Affects Sensitive Data Security
CVE-2026-19306

7.7HIGH

Key Information:

Vendor

IBM

Vendor
CVE Published:
4 September 2026

What is CVE-2026-19306?

IBM Langflow OSS from version 1.0.0 to 1.11.2 is susceptible to a file access vulnerability allowing authenticated attackers to read arbitrary files from the server's filesystem. This serious weakness enables adversaries to retrieve sensitive materials, including secret keys, JWT signing keys, application databases, and other tenant directories by providing absolute paths or traversal sequences in the files parameter during a build request. The embedded file contents, transmitted to the model endpoint, can lead to significant data breaches, as containment measures intended to restrict local file access are bypassed through the Chat Input to Message attachment pipeline.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.11.2

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.