CVE-2026-84889

8.8

IBM · Langflow OSS

IBM Langflow OSS versions 1.0.0 through 1.10.3 are vulnerable to path traversal, which could allow a remote authenticated attacker to achieve arbitrary code execution.

Executive summary

A high-severity path traversal vulnerability in IBM Langflow OSS allows authenticated remote attackers to execute arbitrary code, posing a significant risk to system integrity and confidentiality.

Vulnerability

This vulnerability is categorized as a path traversal flaw (CWE-22) where improper limitation of a pathname to a restricted directory permits an authenticated user to bypass security controls and execute arbitrary code on the underlying host.

Business impact

Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary code with the privileges of the application process. Given the CVSS score of 8.8, this poses a severe risk of full system compromise, unauthorized data access, and potential lateral movement within the network infrastructure.

Remediation

Immediate Action: Upgrade to IBM Langflow OSS version 1.11.0 as specified in the vendor security advisory.

Proactive Monitoring: Review application access logs for unusual file system access patterns or unexpected command execution attempts originating from authenticated user sessions.

Compensating Controls: Implement strict file system permissions for the service account running Langflow OSS and utilize a Web Application Firewall to block requests containing path traversal sequences.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability, combined with the potential for arbitrary code execution, necessitates immediate action. Administrators should prioritize upgrading to version 1.11.0 to eliminate the underlying path traversal risk and prevent unauthorized system manipulation.

More IBM CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources