Unrated severityNVD Advisory· Published Jul 17, 2026· Updated Jul 20, 2026
Path Traversal Vulnerability in File Component Leading to Arbitrary File Read and Authentication Bypass
CVE-2026-7872
Description
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.
Affected products
2- Range: >=1.0.0,<1.10.0
- Range: 1.0.0 - 1.10.0
Patches
Vulnerability mechanics
References
1- www.ibm.com/support/pages/node/7278934mitrevendor-advisorypatch
News mentions
0No linked articles in our index yet.