Impact
The vulnerability is a server‑side request forgery that permits an attacker who is authenticated to the IBM Langflow OSS application to cause the system to send arbitrary HTTP requests on the attacker’s behalf. This functionality can be leveraged for network reconnaissance, access to internal services, or other downstream exploits. The flaw is a classic SSRF weakness as noted by CWE‑918 and may lead to compromise if internal resources are accessed.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.11.1 are impacted. These include the releases listed in the known CPEs for 1.0.0 and 1.11.1. The latest disclosed fix is in version 1.11.2 released on PyPI.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑moderate severity. EPSS data are not available, and the issue is not yet cataloged in CISA’s KEV. Exploitation requires the attacker to be authenticated to the application, after which they can craft malicious request targets. The primary threat is the ability to perform internal network enumeration or further pivot attacks through outbound requests from the host.
OpenCVE Enrichment