← Retour
CVE-2026-7872
high
CVSS 7.5
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
Résumé
IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files...
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2026-7872** a été découverte dans jwt.
Des informations confidentielles peuvent être exposées. Score CVSS : 7.5/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « jwt CVE-2026-7872 » sur le site de l'éditeur.
CVE-2026-7872 (jwt) — CWE-22 / CVSS v3 7.5
Vecteur d'attaque : distant (réseau) / non authentifié / sans interaction utilisateur
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
IBM Langflow OSSの認証済み攻撃者が任意のファイルを読み取れる脆弱性。
📍 Périmètre concerné
IBM Langflow OSS バージョン 1.0.0 から 1.10.0
🔥 Gravité
JWT署名キーを直接取得可能で、トークン偽造につながるので深刻。
🔧 Comment corriger
IBMによるパッチの適用を推奨。最新の公式アップデートを確認。
🛡️ Contournement
該当バージョンを使用中の環境でファイルアクセス権限を厳格化。
🔍 Détection
ログインユーザーのファイルアクセスを監視し、不審な動作を検知する。