Impact
IBM Langflow OSS versions from 1.0.0 through 1.10.0 contain a flaw that allows an attacker to supply arbitrary code to the service. The vulnerability arises from an improper control of user‑provided input, enabling the execution of injected code with the privileges of the running instance. This flaw is classified as a code injection weakness (CWE‑94) and results in full compromise of the host system if exploited.
Affected Systems
The affected product is IBM Langflow OSS. Versions 1.0.0 through 1.10.0 are impacted as indicated by the vendor’s advisories and the listed CPE ranges. Versions beyond 1.10.0 are not known to be affected.
Risk and Exploitability
The CVSS score of 9.9 indicates a very high severity, while the EPSS score of less than 1% suggests that the probability of exploitation in the wild is currently low. The vulnerability is not yet listed in CISA’s KEV catalog. An attacker can likely exploit the flaw by sending malicious code to the Langflow OSS service over the network, which is then executed by the application process with its underlying permissions.
OpenCVE Enrichment