AI description
CVE-2026-7524 is a path traversal vulnerability affecting IBM Langflow OSS versions 1.0.0 through 1.9.1. The flaw originates from the improper validation of symbolic links during the extraction of archive files. This vulnerability allows an attacker to craft malicious archives that, when processed by Langflow, can write files to arbitrary locations outside the intended directory. This unauthorized file writing capability can ultimately lead to remote code execution on affected servers, requiring no authentication or user interaction for exploitation.
- Description
- IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.
- Source
- psirt@us.ibm.com
- NVD status
- Analyzed
- Products
- langflow
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- psirt@us.ibm.com
- CWE-22
- Hype score
- Not currently trending
CVE-2026-7524. 0day Intel: π¨ #Langflow Multi-CVE Exploit Kit π‘ CVE-2026-7524 (Path Traversal) | CVE-202
@lyrie_ai
13 Jul 2026
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
π¨ #Langflow Multi-CVE Exploit Kit π‘ **CVE-2026-7524 (Path Traversal) | CVE-2026-7700 (Lambda eval) | CVE-2026-7687 (CodeParser CMD Injection)** 𧬠**Multi-Vector RCE Exploitation Framework** π **Exploitation Chain:** 1. Create tar.gz with payload file + symlink poin
@YogSoth0
20 Jun 2026
5218 Impressions
18 Retweets
92 Likes
45 Bookmarks
3 Replies
0 Quotes
Over the last few months, I researched Langflow, n8n, and Activepieces. The result is 9 zero-days and a BlueHat IL talk π οΈ π¨ CVE-2026-7524 (Critical - 9.8) π¨ CVE-2026-48519 (Critical - 9.6) β οΈ CVE-2026-7528 (High - 7.1) π CVE-2026-42228 (Moderate - 6.3) π CV
@vbCrLf
15 Jun 2026
104 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Over the last few months, I dove into the internals of Langflow, n8n, and Activepieces. The result is 9 zero-days and a BlueHat IL talk π οΈ π¨ CVE-2026-7524 (Critical - 9.8) π¨ CVE-2026-48519 (Critical - 9.6) β οΈ CVE-2026-7528 (High - 7.1) π CVE-2026-42228 (Modera
@vbCrLf
15 Jun 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Over the last few months, I dove into the internals of Langflow, n8n, and Activepieces. The result is 9 zero-days and a BlueHat IL talk π οΈ π¨ CVE-2026-7524 (Critical - 9.8) π¨ CVE-2026-48519 (Critical - 9.6) β οΈ CVE-2026-7528 (High - 7.1) π CVE-2026-42228 (Modera
@vbCrLf
15 Jun 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
# Langflow Multi-CVE Exploit Kit **CVE-2026-7524 (Path Traversal) | CVE-2026-7700 (Lambda eval) | CVE-2026-7687 (CodeParse> **Military-Grade Multi-Vector RCE Exploitation Framework** #exploit #0days #CVE #CVSS #security #hacking https://t.co/hB4tr07PJW
@YogSoth0
15 Jun 2026
182 Impressions
0 Retweets
7 Likes
0 Bookmarks
1 Reply
0 Quotes
New 0days multi-exploit kit: Langflow Multi-CVE Reconnaissance Scanner Targets: CVE-2026-7524 (Path Traversal), CVE-2026-7700 (Lambda eval), CVE-2026-7687 (CodeParser) Military-grade async scanner with vulnerability fingerprinting and exploitability scoring. Soon on gibliz h
@YogSoth0
14 Jun 2026
220 Impressions
1 Retweet
4 Likes
1 Bookmark
1 Reply
0 Quotes
π¨ CVE-2026-7524 β CVSS 9.8/10 ββββββββββ IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/LKalsDQ8nc
@OrizonCyber
27 May 2026
57 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*",
"matchCriteriaId": "75C9A6EE-2880-4DF8-9FA7-983625105F8D",
"versionEndIncluding": "1.9.1",
"versionStartIncluding": "1.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]