{"data":{"id":"b3ee3b2e-b65c-4f76-a98f-6cf783dd44e2","title":"CVE-2026-17622: IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to","summary":"IBM Langflow OSS (an open-source tool for building AI applications) versions 1.0.0 through 1.10.2 has a security weakness that lets an authenticated attacker (someone with login access) read sensitive information they shouldn't be able to access. The problem is that the software doesn't properly restrict which files and folders users can view, allowing them to access data outside their permitted areas.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-17622","publishedAt":"2026-09-04T17:16:55.227Z","cveId":"CVE-2026-17622","cweIds":["CWE-22"],"cvssScore":"6.5","cvssSeverity":"medium","severity":"medium","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-04T17:16:55.227Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}