CyberRota Analysis
AI-GeneratedIBM Langflow OSS versions 1.0.0 to 1.10.3 are vulnerable to unauthorized file access, allowing attackers to read sensitive files from the server's filesystem, including user documents, JWT signing secrets, and environment variables, through a crafted MCP `resources/read` request. This vulnerability poses a medium severity risk, as it can lead to data exposure and potential further exploitation. Organizations using affected versions should prioritize patching to mitigate the risk of sensitive data leakage.
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path traversal sequence in the filename.
Related CVEs
Other vulnerabilities affecting the same vendor(s)