Impact
The vulnerability allows an authenticated user to cause the system to fetch arbitrary URLs, which the application does not adequately validate. This server‑side request forgery can expose internal services to the attacker, enabling network reconnaissance and potentially serving as a foothold for other attacks. The flaw is identified as CWE‑918 and does not, by itself, provide privilege escalation but creates a significant attack surface.
Affected Systems
Products affected are IBM’s Langflow OSS versions 1.0.0 through 1.11.2. The vulnerability is present in any deployment of these releases and is not limited to a specific operating system or environment.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The lack of an EPSS score means there is no quantifiable data on exploitation frequency, and the vulnerability is not currently listed in the CISA KEV catalog. Typical access requires user authentication, and exploitation would involve sending crafted requests from the application to unintended endpoints. The potential impact could include internal network discovery and the facilitation of subsequent attacks against internal services.
OpenCVE Enrichment