Impact
IBM Langflow OSS versions 1.0.0 through 1.10.2 contain a server-side request forgery flaw caused by missing URL validation in flow components. A remote authenticated attacker can supply arbitrary URLs to the flow when executing a request, causing the application to perform HTTP requests to internal or external resources. The attacker could potentially read or download sensitive files, exfiltrate data, or use the application as a pivot to reach other internal network services, compromising confidentiality and integrity of data within the environment.
Affected Systems
The affected product is IBM Langflow OSS. The vulnerable releases span from version 1.0.0 up to and including 1.10.2. Any deployment running these versions is potentially impacted.
Risk and Exploitability
The CVSS score for this vulnerability is 5, indicating a medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through an authenticated API request to the vulnerable flow components; the attacker needs valid credentials to trigger the SSRF. No public exploit is known, but the moderate score reflects the potential for significant information disclosure if exploited.
OpenCVE Enrichment