CVE-2026-7524 Details
Description
IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.
A remote code execution vulnerability exists in IBM Langflow OSS versions 1.0.0 through 1.9.1. The issue arises from improper validation of symbolic links during the extraction of tar archives, allowing attackers to exploit symlinks to access arbitrary files on the file system. In scenarios where users can upload documents, a crafted tar file could be used to link to sensitive files, such as Langflow OSS' JWT secret key. Once these files are processed and stored in the vector database, the attacker could retrieve sensitive information through chatbot queries, potentially leading to authentication bypass and remote code execution via the Python Interpreter node.
Users are advised to upgrade IBM Langflow OSS to version 1.9.2.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ibm.com/support/pages/node/7273426 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| langflow langflow | >= 1.0.0, <= 1.9.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | Initial Analysis | [email protected] |
| May 27, 2026 | New CVE Received | [email protected] |