CVE-2026-4502: Arbitrary File Write and Remote Code Execution Vulnerability in Langflow v2 API
IBM Langflow Desktop 1.2.0 through 1.8.4 Langflow could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4502?
CVE-2026-4502 is classified as a critical vulnerability due to its potential for arbitrary file write and remote code execution.
How do I fix CVE-2026-4502?
To remediate CVE-2026-4502, upgrade IBM Langflow Desktop to a version higher than 1.8.4.
Who is affected by CVE-2026-4502?
CVE-2026-4502 affects users of IBM Langflow Desktop versions 1.2.0 through 1.8.4.
What kind of attack does CVE-2026-4502 enable?
CVE-2026-4502 enables an authenticated attacker to perform directory traversal attacks, potentially executing arbitrary code.
Is authentication required to exploit CVE-2026-4502?
Yes, CVE-2026-4502 requires an attacker to be authenticated to exploit the vulnerability.