Impact
IBM Langflow OSS versions 1.0.0 through 1.10.3 contain a flaw that allows any authenticated user to use a built‑in component to read arbitrary server environment variables. The vulnerability bypasses security controls that are supposed to disable custom components, revealing confidential secrets that could include API keys or database credentials. It is classified as CWE‑200, representing information disclosure and directly threatens the confidentiality of the system.
Affected Systems
The affected product is IBM Langflow OSS. Versions 1.0.0, 1.10.3, and all releases in between are vulnerable. The vendor’s official advisory recommends upgrading to version 1.11.0 or newer to remediate the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, reflecting that the attacker must first be authenticated to the application. The EPSS score is not available, so the current likelihood of exploitation is unclear. The vulnerability is not listed in the CISA KEV catalog, and no remote exploitation vector is described in the advisory. The attack likely requires access to a valid user account and the ability to invoke the vulnerable component within the application interface.
OpenCVE Enrichment