Impact
IBM Langflow OSS contains a permission flaw that lets an attacker reuse another user’s FAISS namespace. This flaw can expose private vector data and allow the attacker to manipulate future query results. The impact is therefore primarily confidentiality loss for other users and a moderate integrity issue through persistent poisoning of returned results.
Affected Systems
The vulnerability is present in IBM Langflow OSS version 1.0.0 through 1.10.1. These versions expose unauthenticated and insufficiently authorized API endpoints that enable the impersonation scenario described.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high severity, yet the EPSS score of less than 1 % shows a very low exploitation probability at present. The flaw is not listed in the CISA KEV catalog. It is likely exploited via network traffic that targets the exposed API endpoints, with no special privilege required. Attackers can send crafted requests to reference another user’s vector namespace, read private data, and inject poisoned vectors into the query pipeline.
OpenCVE Enrichment