Executive brief
IBM Langflow OSS, a framework for building AI applications, contains a critical vulnerability in how it handles uploaded files. An attacker can upload a specially crafted archive file to steal sensitive internal data, such as security keys, which can then be used to take full control of the server. This could lead to unauthorized access to private AI models, data theft, or complete system compromise.
Technical details
A path traversal vulnerability (CWE-22) exists in Langflow OSS components derived from BaseFileComponent, including Docling, Read File, and NVIDIA Retriever Extraction. The vulnerability resides in the _unpack_bundle function, which fails to properly validate symbolic links within tar archives during extraction. An unauthenticated remote attacker can exploit this by uploading a malicious tar file containing symlinks that point to sensitive local files, such as the JWT secret key. By retrieving these files through chatbot queries or vector database storage, the attacker can forge authentication tokens and eventually achieve remote code execution via the Python Interpreter node. The issue is resolved in version 1.9.2.
Affected products
- IBM Langflow OSS 1.0.0-1.9.1
Timeline
- 2026-05-19: advisory: Initial publication by IBM
- 2026-05-27: disclosed: NVD publication date