Impact
This vulnerability allows an attacker to inject dangerous environment variables into the MCP (Model Context Protocol) stdio launcher of IBM Langflow OSS. Because the blocklist for protected environment variables does not include SHELLOPTS, BASHOPTS, or PS4, the application can execute arbitrary shell commands. The flaw is a classic command injection (CWE-78 style) and can lead to the host system running the application being fully compromised.
Affected Systems
IBM Langflow OSS releases 1.0.0 through 1.10.1 are affected. This includes the versions listed by the vendor and any derivative deployments that have not applied the vendor‑provided patch.
Risk and Exploitability
The CVSS score of 9.8 marks this flaw as critical. The EPSS score indicates a very low exploitation probability (<1%). The flaw is fully exploitable unauthenticated through exposed API endpoints. The vulnerability is not yet listed in CISA’s KEV catalog. An attacker who can reach the MCP stdio launcher, for example through the web or network, can trigger arbitrary code execution with the privileges of the Langflow process.
OpenCVE Enrichment