AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-7646

MEDIUM · CVSS 6.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.10.3 are vulnerable to unauthorized file access, allowing attackers to read sensitive files from the server's filesystem, including user documents, JWT signing secrets, and environment variables, through a crafted MCP `resources/read` request. This vulnerability poses a medium severity risk, as it can lead to data exposure and potential further exploitation. Organizations using affected versions should prioritize patching to mitigate the risk of sensitive data leakage.

CVE
CVE-2026-7646
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path traversal sequence in the filename.

Related CVEs

Other vulnerabilities affecting the same vendor(s)