VulnWatch VulnWatch
← Back to dashboard
High nvd · CVE-2026-7667

CVE-2026-7667: IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacke

Published Jul 17, 2026 CVSS 8.8

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header (e.g., filename="../../../target/path" ), enabling arbitrary file write operations with attacker-controlled content to any path accessible by the Langflow process.

Affected AI Products

langflow
Get the weekly digest. Every Monday: top AI security stories of the week. Free.