Skip to content
MediumVulnerability

CVE-2026-93448: IBM Langflow OSS path traversal exposes sensitive information

Identifier
CVE-2026-93448
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.7%

Summary

IBM Langflow OSS versions 1.0.0 through 1.12.2 contain a flaw where a pathname is not properly limited to a restricted directory. A remote authenticated attacker can exploit this to obtain sensitive information.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.