IBM Langflow Desktop Directory Traversal Vulnerability Allowing Arbitrary File Write

Vulnerability

A directory traversal vulnerability has been identified in IBM Langflow Desktop versions 1.2.0 through 1.8.4. This vulnerability allows authenticated attackers to send specially crafted URL requests that include 'dot dot' sequences to traverse directories and write arbitrary files on the system. The issue arises because the application improperly sanitizes multipart upload filenames, enabling path traversal and arbitrary file writing outside of intended directories.

Impact

Exploitation of this vulnerability could lead to unauthorized file writing on the system, with the potential for remote code execution, as the written files could be executed with the privileges of the backend service.

Remediation

Users are advised to upgrade to IBM Langflow Desktop version 1.9.0 or newer. Instructions for downloading Langflow Desktop are available on the Langflow website.

Added: Apr 30, 2026, 9:25 PM
Updated: Apr 30, 2026, 9:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.2
exploitability
3.3
remediation
0.0
relevance
6.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.