{"data":{"id":"a004f117-fea9-45b5-b86c-4d2b32f71fba","title":"CVE-2026-13445: IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read an","summary":"IBM Langflow OSS (open-source software) versions 1.0.0 through 1.10.1 has a vulnerability where a logged-in attacker can misuse the SaveToFile component (a tool that saves data to files) to access and change files belonging to other users by using absolute paths (complete file addresses). The attacker can either read and copy other users' files to their own account (confidentiality breach, where private information is exposed) or overwrite those files with fake data (integrity breach, where data is corrupted or replaced).","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13445","publishedAt":"2026-07-17T21:17:05.473Z","cveId":"CVE-2026-13445","cweIds":["CWE-639"],"cvssScore":"8.1","cvssSeverity":"high","severity":"high","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-17T21:17:05.473Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}