Impact
IBM Langflow OSS versions 1.0.0 through 1.10.3 contain an improper validation of Python code during AST‑based security scanning. Based on the description, it is inferred that a remote authenticated attacker who can supply or modify component code can trigger code execution on the server, giving full control over the host and allowing the attacker to compromise confidentiality, integrity, and availability. This flaw maps to CWE‑94, a code injection weakness.
Affected Systems
The vulnerable instances are IBM’s Langflow OSS, specifically releases 1.0.0 to 1.10.3. Any environment running these versions, regardless of deployment size, is susceptible if it accepts user‑generated or custom components.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. Although the EPSS score is unavailable, the vulnerability is not currently listed in the CISA KEV catalog, but its impact is significant. Based on the description, it is inferred that attackers who can authenticate to the system and have permission to create or edit components can submit malicious Python code during component creation or validation, leading to full code execution on the host system. This vulnerability requires only an authenticated session and the ability to manipulate custom components, which many users possess, making exploitation plausible.
OpenCVE Enrichment