VulnWatch VulnWatch
← Back to dashboard
Medium nvd · CVE-2026-14470

CVE-2026-14470: IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An at

Published Sep 4, 2026 CVSS 6.5

IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

Affected AI Products

langflow
Get the weekly digest. Every Monday: top AI security stories of the week. Free.