Impact
The flaw permits a remote authenticated attacker to execute arbitrary OS commands through injection of special elements that are not properly neutralized in command strings. An attacker could gain full control of the underlying host, leading to compromise of confidentiality, integrity, and availability.
Affected Systems
IBM Langflow OSS 1.0.0 through 1.10.3 are vulnerable. These releases are available as open‑source on GitHub and are distributed under the IBMLangflow OSS license.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity. The EPSS score is not provided, so the exact exploitation probability is unknown, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires authentication, meaning an attacker must first obtain valid credentials or use a privileged user. Once authenticated, the command injection can be leveraged to take complete control of the affected system.
OpenCVE Enrichment