File Access Vulnerability in IBM Langflow OSS Affects Sensitive Data Security
CVE-2026-19306
7.7HIGH
What is CVE-2026-19306?
IBM Langflow OSS from version 1.0.0 to 1.11.2 is susceptible to a file access vulnerability allowing authenticated attackers to read arbitrary files from the server's filesystem. This serious weakness enables adversaries to retrieve sensitive materials, including secret keys, JWT signing keys, application databases, and other tenant directories by providing absolute paths or traversal sequences in the files parameter during a build request. The embedded file contents, transmitted to the model endpoint, can lead to significant data breaches, as containment measures intended to restrict local file access are bypassed through the Chat Input to Message attachment pipeline.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.11.2