Vulnary
← back to the feed
Critical· 9.9

CVE-2026-8859

IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a path traversal flaw in the APIRequest component's 'Save to File' feature. When this feature is enabled, filenames taken from HTTP response Content-Disposition headers are not validated, allowing an attacker who controls an external HTTP server to inject sequences like ../ and write arbitrary files to any location the Langflow process can access. This vulnerability is rated critical with a CVSS score of 9.9.

publishedJul 17, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
9.9
critical · how bad it is
exploitation · epss
<1%
30th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 1, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

IBM Langflow OSS 1.0.0 through 1.10.0

02

Real-world impact

An attacker can write files to unintended locations on the system running Langflow, potentially leading to further compromise.

03

Why this severity

CVSS base score 9.9 (Critical) reflects network attack vector, low complexity, low privileges required, no user interaction, and high impacts to confidentiality, integrity, and availability.

04

What to do about it

no official fix yet
recommended steps
  1. 01No official fix is available yet.
interim mitigations
  • Disable the 'Save to File' feature if not required.
  • Restrict network access to the Langflow service to trusted sources.
  • Monitor and validate filenames from external HTTP responses before use.

Remediation guidance is based on general secure‑coding practices because the sources do not specify a vendor patch.

05

Timeline

  1. Jul 17, 2026 · 16d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 23, 2026 · 10d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredLow
User interactionNone needed
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →