Impact
IBM Langflow OSS 1.0.0–1.10.3 contains an OS command injection flaw in the Model Context Protocol (MCP) server configuration. Improper validation of the command field allows a remote authenticated attacker to inject and execute arbitrary shell commands on the host, giving full control of the operating system.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected by this vulnerability. All releases in that range, including the cpe entries for 1.0.0 and 1.10.3, are vulnerable.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is high severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog. The attack vector is remote but requires authentication to the MCP endpoint, so any user who can log in can trigger the exploit by submitting a crafted command via the legitimate API.
OpenCVE Enrichment