Impact
This vulnerability allows attackers to view and modify build jobs that belong to other users because the API endpoints that retrieve logs and create new builds do not enforce proper authorization checks. The weakness is a classic improper access control flaw, classified as CWE-639. An attacker could gain access to build artifacts or change build configurations, potentially affecting the confidentiality and integrity of data.
Affected Systems
The affected product is IBM:Langflow OSS, with vulnerable releases from 1.0.0 up to and including 1.10.1. All users running these specific versions are at risk unless the software is upgraded.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. The EPSS score of 0.215% indicates a low exploitation probability, suggesting that active attacks are unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. Based on the description, exploitation can occur through unauthenticated access to the build creation endpoint or via authenticated use of the log retrieval endpoint; the attack does not appear to require privileged system access or complex prerequisites, so the potential for exploitation remains significant.
OpenCVE Enrichment