Impact
IBM Langflow OSS versions 1.0.0 through 1.10.1 contain insecure API endpoints that do not enforce proper authorization. An attacker can create a flow that references the exact persist_directory and collection_name used by another user, thereby retrieving that user's private vector documents. Additionally, the attacker can inject arbitrary documents into the same collection, corrupting shared data. This leads to a breach of confidentiality and integrity for users’ private information.
Affected Systems
Affected systems are IBM Langflow OSS installations running any version from 1.0.0 up to and including 1.10.1. The product can be updated through the IBM Langflow OSS PyPI package.
Risk and Exploitability
The CVSS base score is 8.1, indicating high severity. EPSS score of < 1%, indicating a very low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, but because the flaw can be exploited remotely with only unauthenticated API requests, the practical exploitation likelihood is high. Attackers can send crafted API calls over the network to retrieve or tamper with private flows without any user interaction or elevated privileges.
OpenCVE Enrichment