What is CVE-2026-7658?
CVE-2026-7658 is a path traversal vulnerability in the username field of IBM Langflow OSS versions 1.0.0 through 1.10.3. It allows attackers to bypass containment checks, leading to arbitrary directory deletion, cross-tenant data destruction, and possible JWT signing key compromise. Immediate patching is strongly recommended for affected deployments.
Azərbaycanca: CVE-2026-7658 boşluğu IBM Langflow OSS 1.0.0-dən 1.10.3-ə qədər versiyalarda istifadəçi adı sahəsində path traversal zəifliyidir. Bu, autentifikasiya nəzarətini keçərək ixtiyari qovluq silmə, çarpaz kirayəçi məlumatlarının məhv edilməsi və JWT imza açarının pozulması kimi ciddi fəsadlara səbəb ola bilər. Təsirə məruz qalan sistemlərdə təcili olaraq vendor tərəfindən təqdim edilən yeniləmələr tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: IBM
FAQ2
Which versions of IBM Langflow OSS are affected by CVE-2026-7658?
CVE-2026-7658 affects IBM Langflow OSS versions 1.0.0 through 1.10.3.
What are the main risks if CVE-2026-7658 is exploited?
Exploitation of this vulnerability can lead to arbitrary directory deletion, cross-tenant data destruction, and possible JWT signing key compromise.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.