Impact
IBM Langflow OSS versions 1.0.0 through 1.11.5 do not enforce egress filtering on server‑side URL fetches, creating a server‑side request forgery flaw. The vulnerability permits an unauthenticated attacker to trigger the application to retrieve arbitrary URLs, allowing access to internal network resources, reconnaissance, and potential escalation. Successful exploitation could disclose sensitive data from internal services and enable further attacks such as credential theft or privilege escalation, compromising confidentiality, integrity, and availability of the affected environment.
Affected Systems
The affected products are IBM 1.0.0 up to and including 1.11.5 as identified by the vendor's CNA OSS versions 1.0.0 through 1.11.5 are vulnerable to SSRF via missing egress validation, allowing an unauthenticated attacker to instruct the server to perform arbitrary URL fetches, which can lead to internal network enumeration or facilitate further attacks such as credential theft.
Risk and Exploitability
The CVSS score of 6.5 is risk; however, the EPSS score is < 1% and it is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. The attack vector is an SSRF scenario where an attacker supplies a malicious URL to the server‑side URL fetching component, leading to unauthorized internal network requests.
OpenCVE Enrichment