SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-13445

HIGH · CVSS 8.1 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 through 1.10.1 are vulnerable to exploitation via the SaveToFile component, allowing authenticated attackers to access and manipulate other users' uploaded files by specifying absolute paths. This vulnerability can lead to significant confidentiality and integrity breaches, as attackers can read, append, or overwrite victim files. Organizations using affected versions should prioritize remediation to protect user data and maintain storage security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-13445
Severity
HIGH
CVSS
8.1
EPSS
0.21%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by specifying absolute paths pointing to victim storage locations. In append mode, the attacker's workflow reads victim file contents, appends attacker-controlled data, and uploads a copy containing victim data to the attacker's namespace (confidentiality breach). In overwrite mode, the attacker can replace victim file contents with arbitrary data (integrity breach). This breaks the storage ownership boundary between users.

Related CVEs

Other vulnerabilities affecting the same vendor(s)