Medium severity6.5NVD Advisory· Published Aug 5, 2026· Updated Aug 6, 2026
CVE-2026-7658
CVE-2026-7658
Description
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key deletion leading to session invalidation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: 1.0.0 - 1.10.3
Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7282647nvdVendor Advisory
News mentions
2- Langflow OSS: 24 Vulnerabilities Disclosed Together, Posing Severe RisksVypr Intelligence · Aug 5, 2026
- IBM Langflow OSS: 23 Vulnerabilities Disclosed Together, Enabling Code Execution and Data BreachesVypr Intelligence · Aug 5, 2026