以下是该漏洞描述信息的中文翻译: IBM Langflow OSS 1.0.0 至 1.11.5 版本中的 Langflow 可能允许经过身份验证的攻击者访问其他用户的敏感文件,原因是“文件/读取文件”组件中存在访问控制不当的问题。当通过 端点执行工作流(flows)时,应用程序允许组件的输入引用使用任意用户或工作流标识符的存储路径,而不会验证其所有权关系。拥有低权限身份验证访问权限的攻击者可以提供一个精心构造的文件路径,指向其他用户的存储命名空间,从而导致后端读取并返回其他用户上传文件的内容。此漏洞绕过了文件管理
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | Langflow OSS | 1.0.0 ~ 1.11.5 |
cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81204 | 9.8 CRITICAL | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-79724 | 9.8 CRITICAL | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-85025 | 9.8 CRITICAL | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-78573 | 9.8 CRITICAL | IBM ContextForge MCP Gateway is affected by use of default credentials |
| CVE-2026-82107 | 9.6 CRITICAL | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-82100 | 9.6 CRITICAL | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-80424 | 9.1 CRITICAL | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-19646 | 9.1 CRITICAL | Multiple vulnerabilities affect IBM License Key Server Administration and Reporting Tool a |
| CVE-2026-79742 | 8.8 HIGH | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-78569 | 8.8 HIGH | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-82095 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-82092 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-81211 | 8.8 HIGH | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-81941 | 8.8 HIGH | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-78575 | 8.8 HIGH | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-81940 | 8.8 HIGH | Langflow is vulnerable to arbitrary code execution due to multiple incomplete code securit |
| CVE-2026-81554 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-81551 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-81550 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities due to open source software |
| CVE-2026-75777 | 8.8 HIGH | Multiple vulnerabilities in IBM Aspera Enterprise Webapps |
Showing top 20 of 49 CVEs. View all on vendor page → →
No comments yet