Impact
The vulnerability is an improper authentication flaw in the password reset endpoint of IBM Langflow OSS. A remote authenticated attacker, who has access to an account, can change that account's password without providing the current or any additional verification credentials. This allows the attacker to take control of the affected account, potentially gaining full access to the application data and any integrations the account may have. The weakness is identified as CWE-287.
Affected Systems
IBM Langflow OSS versions from 1.0.0 through 1.10.2 are vulnerable. The latest unpatched release listed is 1.10.2. Upgrading to version 1.10.3 or later eliminates the flaw.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is below 1%, indicating a very low likelihood of exploitation. The issue is not listed in the CISA KEV catalog. The attack requires that the attacker be authenticated to the target application and able to send a password reset request, allowing the attacker to change the password of an account they have already logged into. This makes the vulnerability accessible to remote attackers with valid credentials.
OpenCVE Enrichment