Impact
IBM Langflow OSS versions 1.0.0 through 1.12.2 contain an improper access control flaw (CWE-284) that enables a remote authenticated attacker to retrieve sensitive information. The vulnerability requires the attacker to be authenticated to the application, after which they can read privileged data that should be restricted to authorized users. This weakness can lead to the compromise of confidential business data, user personal information, or other protected resources accessible within the Langflow environment.
Affected Systems
The affected product is IBM Langflow OSS. All releases from version 1.0.0 up to but not including 1.12.3 are vulnerable. Users deploying any of these versions should verify their installation versions and plan to upgrade.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score is not available, suggesting limited public exploitation data. The vulnerability is not listed in CISA’s KEV catalog, implying it is not a widely known exploited vulnerability. A remote authenticated attacker—potentially one who has compromised valid credentials or gained access via weak authentication—can exploit the flaw to obtain sensitive data. The attack vector is remote; local restrictions on the host are insufficient to mitigate the exposed access control issue.
OpenCVE Enrichment