Impact
IBM Langflow OSS versions 1.0.0 through 1.10.0 allow attackers to submit malicious components that import socket or urllib, which the security scanner incorrectly marks as "validated": true. Based on the description, it is inferred that the flaw involves a reflected outbound request (CWE-918) that leads to arbitrary Python code execution with root privileges on the host. As a result, an adversary can steal AWS credentials via IMDSv1 SSRF, exfiltrate files from the container file system, or pivot to internal services such as PostgreSQL and Redis.
Affected Systems
IBM Langflow OSS, versions 1.0.0 up to and including 1.10.0, is the only product affected according to CNA data.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.6, indicating a critical severity. The EPSS score is <1%, reflecting a very low but nonzero probability of exploitation. Although the KEV catalog does not list it, the impact—root-level code execution and lateral movement—requires immediate attention. Attackers can exploit this via network-based submission of malicious components, elevating the risk for all exposed Langflow instances.
OpenCVE Enrichment