Medium severity6.5NVD Advisory· Published Apr 30, 2026· Updated May 11, 2026
CVE-2026-4502
CVE-2026-4502
Description
IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.ibm.com/support/pages/node/7271097nvdVendor Advisory
News mentions
4- ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ StoriesThe Hacker News · May 14, 2026
- ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and MoreThe Hacker News · May 11, 2026
- Metasploit Wrap-Up 04/25/2026Rapid7 Blog · Apr 24, 2026
- 23rd March – Threat Intelligence ReportCheck Point Research · Mar 23, 2026