Impact
IBM Langflow OSS versions 1.0.0 through 1.10.3 include an issue where the Model Context Protocol server does not fully filter unsafe Docker volume-mount and device-mapping arguments. An authenticated attacker who can reach the MCP server can therefore read, alter, or expose sensitive files on the host machine, compromising confidentiality and integrity and potentially enabling further lateral movement.
Affected Systems
The vulnerability affects IBM Langflow OSS 1.0.0 through 1.10.3. IBM recommends upgrading to version 1.11.0 or newer to eliminate the flaw. The affected product is IBM Langflow OSS.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attack requires authenticated access to the application and local Docker-based MCP servers; appropriate privileges are needed to mount volumes or devices on the host, making privileged or local attackers capable of exploitation.
OpenCVE Enrichment