CVE-2026-14470
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Sep 04, 2026
Vendor
unknown
Description
IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.