Impact
IBM Langflow OSS versions 1.0.0 through 1.10.3 contain a code injection flaw that allows a remote authenticated attacker to run arbitrary code. The vulnerability arises during component generation, validation, and custom component handling, where unsanitized input can be executed as code. This flaw enables attackers to compromise confidentiality, integrity, and availability of the system, granting them full command execution within the application’s environment.
Affected Systems
IBM Langflow OSS, specifically versions 1.0.0 to 1.10.3. The issue does not affect newer releases such as 1.11.0 and above.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. EPSS is not available, so a precise likelihood estimate cannot be given, but the flaw is known to be exploitable by authenticated users, implying a moderate to high risk of real‑world attack. The vulnerability is not listed in CISA’s KEV catalog, yet the impact level warrants immediate remediation.
OpenCVE Enrichment