Junglewise Threat Intelligence

CVE-2026-4502: IBM Langflow Desktop path traversal in v2 API

CVE-2026-4502 · Severity: medium · CVSS 6.5 · Published 2026-04-30

Technologies: IBM Langflow Desktop. Vendors: IBM.

Executive brief

IBM Langflow Desktop, a tool used for building AI applications, contains a security flaw in how it handles file uploads. An authorized user could exploit this to save malicious files to sensitive areas of the computer's operating system. This could lead to a complete system takeover or the execution of unauthorized commands, potentially compromising corporate data and AI workflows.

Technical details

A path traversal vulnerability (CWE-22) exists in the IBM Langflow Desktop v2 API, specifically within the POST /api/v2/files/ endpoint. The application fails to properly sanitize multipart upload filenames, allowing an authenticated attacker to use 'dot dot' (/../) sequences to escape the intended upload directory. By writing arbitrary files to sensitive locations on the host filesystem, an attacker can achieve remote code execution with the privileges of the backend service. This vulnerability reportedly bypasses previous protections implemented for CVE-2025-68478. Users are advised to upgrade to version 1.9.0 or newer.

Affected products

  • IBM Langflow Desktop 1.2.0 - 1.8.4

Timeline

  • 2026-04-28: advisory: Initial publication by IBM
  • 2026-04-30: disclosed: NVD publication date
  • 2026-05-11: other: NIST initial analysis and CPE enrichment

References

Related threats