{"data":{"id":"dda9fa85-6790-465b-8305-2747a1f13791","title":"CVE-2026-7658: IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path t","summary":"IBM Langflow OSS (open-source software) versions 1.0.0 through 1.10.3 has a vulnerability where the username field is not properly checked, allowing attackers to use path traversal (a technique to access files outside intended directories by using sequences like '../'). This flaw could let attackers delete files from any directory, destroy data belonging to other users, or remove JWT signing keys (cryptographic keys used to verify user sessions), which would invalidate all user sessions.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7658","publishedAt":"2026-08-05T19:17:43.580Z","cveId":"CVE-2026-7658","cweIds":["CWE-22"],"cvssScore":"6.5","cvssSeverity":"medium","severity":"medium","attackType":[],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow OSS"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-05T19:17:43.580Z","capecIds":["CAPEC-126"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}