NPM · JULY 2026 · CONFIRMED

Critical Vulnerability in IBM Langflow OSS: Arbitrary File Write

CVE-2026-8859Severity: CRITICAL

IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical vulnerability (CVE-2026-8859) allowing attackers to write arbitrary files to unintended locations due to improper input validation.

What happened

The vulnerability exists in the 'Save to File' feature when filenames extracted from HTTP response Content-Disposition headers are not sanitized. This improper input validation can be exploited by attackers to write files to arbitrary locations, potentially leading to system compromise.

Affected components include langflow (npm) versions 1.0.0 through 1.10.0. To mitigate this vulnerability, it is recommended to upgrade to a version of Langflow that includes the fix or apply a workaround if upgrading is not immediately possible.

Multiple independent sources have confirmed this vulnerability, including the NCSC and NVD. For detailed information and CVSS scores, consult the primary sources listed in the threat data.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If langflow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats