Impact
A flaw in how the exec_globals parameter is handled by the Langflow validate endpoint allows an attacker to include code from an untrusted control sphere. The omission is classified as CWE‑829 and permits the execution of arbitrary code with root privileges. Because authentication is not required, the attack can be carried out entirely by remotely crafted requests.
Affected Systems
Version 1.4.2 of the Langflow application is affected. No other versions are listed in the provided material.
Risk and Exploitability
The vulnerability scores 9.8 on the CVSS scale, reflecting a critical impact. The EPSS score of 53 % indicates a high likelihood that this flaw will be actively exploited. It was added to the CISA KEV catalog. Attackers can exploit the flaw by sending a specially crafted request to the validate endpoint from an unauthenticated source, gaining root‑level execution on the host.
OpenCVE Enrichment
Github GHSA