Impact
IBM Langflow OSS versions 1.0.0 through 1.10.3 contain an improper validation of configuration parameters that may allow an attacker with access to the configuration interface to execute arbitrary code on the host. The flaw is characterized as CWE‑184 and enables remote code execution when the configuration endpoint is reachable by malicious input.
Affected Systems
The vulnerability affects IBM Langflow OSS, specifically all releases from 1.0.0 up to and including 1.10.3. Any instance running one of these versions without the fix is susceptible, while versions 1.11.0 and newer are not affected according to the vendor data.
Risk and Exploitability
The CVSS score of 7.2 marks this issue as high severity, yet the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation to date. The attack is likely network‑based, requiring remote interaction with the configuration API. If that API is exposed externally, an attacker could supply crafted configuration data to trigger arbitrary code execution.
OpenCVE Enrichment