What is CVE-2026-12942?
CVE-2026-12942 is a directory traversal vulnerability found in IBM Langflow OSS versions 1.0.0 through 1.10.1. A remote attacker could exploit it by sending a specially crafted URL with "dot dot" sequences to read arbitrary files on the system. Updating to the latest version is recommended to mitigate this issue.
Azərbaycanca: CVE-2026-12942, IBM Langflow OSS-in 1.0.0-dən 1.10.1-ə qədər versiyalarında aşkarlanmış "directory traversal" zəifliyidir. Uzaqdan hücum edən şəxs xüsusi hazırlanmış URL vasitəsilə sistemdəki ixtiyari faylları oxuya bilər. Bu problemi aradan qaldırmaq üçün proqram təminatını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: IBM
FAQ2
Which versions of IBM Langflow OSS are affected by CVE-2026-12942?
This vulnerability affects IBM Langflow OSS versions 1.0.0 through 1.10.1.
What can a remote attacker achieve by exploiting CVE-2026-12942?
A remote attacker can read arbitrary files on the system by sending a specially crafted URL.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.