Impact
Improper validation of module imports in the component generation, validation and custom component handling code paths of IBM Langflow OSS allows a remote authenticated attacker to execute arbitrary code. The vulnerability is captured as CWE‑94, indicating that malicious code can be injected via the module import mechanism. This flaw permits the attacker to run arbitrary programs with the privileges of the running service, potentially compromising the host system, data, and network resources.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected. The vendor recommends installing Langflow OSS 1.11.0 or later to address the issue. Users running the earlier releases should upgrade as soon as possible.
Risk and Exploitability
The CVSS score of 8.5 reflects a high severity for remote code execution, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers would need authenticated access to the application to trigger the flaw, and they could then supply crafted component definitions that result in arbitrary code execution. Because no widely known exploit is listed in KEV, the risk depends largely on customer exposure and the presence of authentication mechanisms.
OpenCVE Enrichment