Impact
IBM Langflow OSS versions 1.0.0 through 1.10.1 contain hard‑coded credentials that are used for inbound authentication, outbound communication, or encryption of internal data. This vulnerability is a CWE‑798 (Use of Hard‑Coded Credentials) weakness, which allows an attacker to gain unauthorized access to the application, potentially hijack sessions, and exfiltrate sensitive data. The exposed credentials also enable brute‑force or credential‑reuse attacks against integrated services, compromising downstream components. This vulnerability can result in full compromise of the affected system as well as associated privileged resources.
Affected Systems
IBM Langflow OSS v1.0.0 to v1.10.1 are affected. The latest fixed version is 1.10.2, to which users are strongly encouraged to upgrade.
Risk and Exploitability
The CVSS score is 9.8, indicating critical severity, while the EPSS score is less than 1 percent, suggesting a very low probability of mass exploitation at present. The vulnerability is listed as not in the CISA KEV catalog, but the lack of authentication on multiple API endpoints makes it highly exploitable when an attacker can reach the service. The likely attack vector involves sending crafted requests to the exposed endpoints over the network, assuming no network segmentation or firewall restrictions are in place. Given the high severity and the fact that credentials are hard‑coded, a successful exploit can lead to remote code execution, denial of service, and credential leakage on both the application and downstream systems.
OpenCVE Enrichment