Executive brief
IBM Langflow Desktop, a tool used for building and deploying AI applications, contains a security flaw that allows users to access files they should not be able to see. By sending a specially crafted request, an attacker with basic user access could view sensitive system files or overwrite application data. This could lead to the theft of confidential information or a complete takeover of the application service.
Technical details
A path traversal vulnerability exists in IBM Langflow Desktop versions 1.8.4 and earlier within the API v2 file upload functionality. The 'POST /api/v2/files' endpoint fails to properly validate and sanitize user-supplied filenames before they are processed by the LocalStorageService. An authenticated remote attacker can exploit this by using 'dot dot' (/../) sequences in a URL or filename to traverse the directory structure. This allows for the unauthorized viewing of arbitrary files or the overwriting of sensitive application files, such as configuration data or databases, potentially leading to remote code execution. The issue is resolved in version 1.9.0.
Affected products
- IBM Langflow Desktop <=1.8.4
Timeline
- 2026-04-28: advisory: Initial publication of IBM security bulletin
- 2026-04-30: disclosed: CVE-2026-3345 published to NVD
- 2026-04-28: patched: Remediation available in version 1.9.0