CyberRota Analysis
AI-GeneratedIBM Langflow OSS versions 1.0.0 to 1.10.3 are vulnerable due to improper validation of the username field, allowing attackers to exploit path traversal vulnerabilities. This can result in severe consequences such as arbitrary directory deletion, cross-tenant data destruction, and the deletion of JWT signing keys, which may invalidate user sessions. Organizations using affected versions should prioritize remediation to mitigate potential data breaches and service disruptions.
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key deletion leading to session invalidation.
Related CVEs
Other vulnerabilities affecting the same vendor(s)