VYPR
Medium severity6.5NVD Advisory· Published Aug 5, 2026· Updated Aug 6, 2026

CVE-2026-7646

CVE-2026-7646

Description

IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP resources/read request with a URL-encoded path traversal sequence in the filename.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

2