Impact
A flaw in how the exec_globals parameter is handled by Langflow's validate endpoint leads to the inclusion of code from an untrusted control sphere. The vulnerability, categorized as CWE-829, permits attackers to run arbitrary commands with root privileges. The flaw requires no authentication, allowing any remote actor to trigger it by crafting a suitable request.
Affected Systems
Langflow version 1.4.2 is affected, as identified by the provided CPE string. No other versions are listed as impacted in the current data.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical risk to confidentiality, integrity, and availability. The EPSS value of 55% indicates a moderate to high likelihood of active exploitation at present. However, the vulnerability is listed in the CISA KEV catalog, signaling that threat actors may target it. Attackers could exploit it by sending an unauthenticated request to the validate endpoint, causing root-level code execution.
OpenCVE Enrichment
Github GHSA