CVE-2026-7524

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
27/05/2026
Last modified:
27/05/2026

Description

IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.

References to Advisories, Solutions, and Tools