CVE-2026-7667 UNKNOWN

CVE-2026-7667

Published: 2026-07-17

Description

IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header (e.g., filename="../../../target/path" ), enabling arbitrary file write operations with attacker-controlled content to any path accessible by the Langflow process.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…