{"data":{"id":"1afa6f1e-34a9-4b14-b462-21dcb1846651","title":"CVE-2026-7869: IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledg","summary":"IBM Langflow OSS versions 1.0.0 through 1.10.3 has a path traversal vulnerability (a flaw where an attacker can access files outside their intended directory) in the Knowledge Bases API endpoint. An authenticated attacker can exploit this by sending specially crafted knowledge base names that aren't properly checked, allowing them to create directories and write files anywhere on the server.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7869","publishedAt":"2026-08-05T19:17:43.700Z","cveId":"CVE-2026-7869","cweIds":["CWE-22"],"cvssScore":"5.4","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow OSS"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-05T19:17:43.700Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}