IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.
Advisories
No advisories yet.
Fixes
Solution
IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.9.2 https://pypi.org/project/langflow/ .
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7273426 |
|
History
Wed, 27 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction. | |
| Title | Path Traversal Vulnerability in File Processing Components Allows Unauthorized File System Access and Potential Remote Code Execution | |
| First Time appeared |
Ibm
Ibm langflow Oss |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:langflow_oss:1.9.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm langflow Oss |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-05-27T13:14:23.238Z
Reserved: 2026-04-30T17:11:41.725Z
Link: CVE-2026-7524
No data.
Status : Awaiting Analysis
Published: 2026-05-27T14:17:35.443
Modified: 2026-05-27T14:53:51.833
Link: CVE-2026-7524
No data.
OpenCVE Enrichment
No data.
Weaknesses