What is CVE-2026-7869?
IBM Langflow OSS versions 1.0.0 through 1.10.3 contain a Path Traversal vulnerability in the Knowledge Bases API, where user-supplied names are used directly to construct file paths without proper sanitization. This could allow an authenticated attacker to perform arbitrary file operations, so affected systems should be patched immediately.
Azərbaycanca: IBM Langflow OSS 1.0.0-dən 1.10.3-ə qədər versiyalarda Knowledge Bases API-də Path Traversal zəifliyi mövcuddur. Bu, istifadəçi tərəfindən təqdim olunan bilik bazası adlarının fayl yolları yaratmaq üçün birbaşa istifadə edilməsi səbəbindən baş verir və autentifikasiya olunmuş hücumçuya ixtiyari fayl əməliyyatları aparmağa imkan verə bilər. Təsirlənən sistemlərdə dərhal rəsmi yamaq tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: IBM
FAQ2
Which versions of IBM Langflow OSS are affected by the CVE-2026-7869 Path Traversal vulnerability?
Versions 1.0.0 through 1.10.3 are affected.
Does exploiting CVE-2026-7869 require authentication?
Yes, the vulnerability can be exploited by an authenticated attacker.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.