CVE-2026-8859
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a path traversal flaw in the APIRequest component's 'Save to File' feature. When this feature is enabled, filenames taken from HTTP response Content-Disposition headers are not validated, allowing an attacker who controls an external HTTP server to inject sequences like ../ and write arbitrary files to any location the Langflow process can access. This vulnerability is rated critical with a CVSS score of 9.9.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
IBM Langflow OSS 1.0.0 through 1.10.0
Real-world impact
An attacker can write files to unintended locations on the system running Langflow, potentially leading to further compromise.
Why this severity
CVSS base score 9.9 (Critical) reflects network attack vector, low complexity, low privileges required, no user interaction, and high impacts to confidentiality, integrity, and availability.
What to do about it
- 01No official fix is available yet.
- ›Disable the 'Save to File' feature if not required.
- ›Restrict network access to the Langflow service to trusted sources.
- ›Monitor and validate filenames from external HTTP responses before use.
Remediation guidance is based on general secure‑coding practices because the sources do not specify a vendor patch.
Timeline
- Jul 17, 2026 · 16d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- ibm.com/support/pages/node/7278924vendor advisory