VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-7869

CVE-2026-7869: IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledg

Published Aug 5, 2026 CVSS 5.4

IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (POST /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create directories and write files anywhere on the server's filesystem.

Affected AI Products

langflow
Get the weekly digest. Every Monday: top AI security stories of the week. Free.