Advisory · CVE-2026-103360
Authenticated path traversal can expose Langflow files
Langflow OSS releases 1.0.0 through 1.12.2 let a remote authenticated attacker read sensitive files through improper restriction of a pathname to its intended directory. IBM rates it high at CVSS 8.1.
- Vendor
- IBM
- Product
- Langflow OSS
- Identifier / CWE
- CVE-2026-103360
CWE-22 - Action timing
- Immediate
Explain it like I’m five
Langflow's filing room is supposed to open only the folders on its shelf, but it accepts shortcuts like 'go up one level.' A logged-in visitor can walk the shortcuts into private drawers and read what is there.
- 01Authenticated access
A remote attacker authenticates to Langflow with valid, low-privilege credentials.
- 02Crafted pathname
The attacker submits a request carrying a pathname with traversal sequences that Langflow fails to confine to its intended directory.
- 03Directory escape
The application resolves the path outside the restricted directory into the wider filesystem.
- 04File read
Sensitive files readable by the service process, potentially including configuration and secrets, are returned to the attacker.
What happened
IBM disclosed CVE-2026-103360 on October 7, 2026: a path traversal flaw in IBM Langflow OSS versions 1.0.0 through 1.12.2. The product does not properly limit a pathname to a restricted directory, so a remote authenticated attacker can read sensitive files outside it. IBM scores it high at CVSS 3.1 8.1, with confidentiality and integrity impacts.
On a Langflow host, files within reach of the service process can include API keys, database credentials, and cloud identity material used by flows and integrations. A read here is often the first step toward deeper compromise, especially in the same bulletin family where read access chains into code execution flaws.
IBM’s bulletin lists no workarounds or mitigations for these Langflow flaws; it recommends addressing them by upgrading.
What to do
- Inventory every Langflow deployment and confirm the running version.
- Upgrade affected instances (1.0.0 through 1.12.2) to the fixed release named in the IBM bulletin.
- Until patched, restrict network access to Langflow and review who holds accounts.
- Review web access and application logs for requests containing path traversal sequences.
- Determine which secrets and credentials the Langflow service account could read, and rotate any that may have been exposed.
Management note
File reads rarely stay file reads on platforms with this many sibling flaws. Assume the exposed surface includes anything the service account can touch, and rotate accordingly rather than hoping the attacker stopped at directory listing.