Impact
The vulnerability is an improper authentication flaw in the password reset endpoint of IBM Langflow OSS. An attacker who can craft a reset request can change a target account's password without providing the current or any verification credentials. This allows the attacker to take control of the affected account, potentially gaining full access to the application data and any integrations the account may have. The weakness is identified as CWE-287.
Affected Systems
IBM Langflow OSS versions from 1.0.0 through 1.10.2 are vulnerable. The latest unpatched release listed is 1.10.2. Upgrading to version 1.10.3 or later eliminates the flaw.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. EPSS is not available, so the likelihood of exploitation is uncertain. The issue is not listed in the CISA KEV catalog. The attack requires only the ability to send a password reset request to the target application, without requiring privileged credentials or complex configurations, making it potentially accessible to remote attackers.
OpenCVE Enrichment