Path Traversal Vulnerability in IBM Langflow OSS
CVE-2026-7658

6.5MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
5 August 2026

What is CVE-2026-7658?

IBM Langflow OSS versions 1.0.0 to 1.10.3 are vulnerable due to inadequate validation of the username field. This flaw allows attackers to exploit path traversal sequences, potentially leading to arbitrary directory deletions, destruction of cross-tenant data, and unauthorized deletion of JWT signing keys, which can invalidate user sessions. Such vulnerabilities pose severe risks to data integrity and application security.

Affected Version(s)

Langflow OSS 1.0.0 <= 1.10.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sergio Cabrera (ddlxstudio) https://github.com/nekros1xx
.