Impact
IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a flaw that allows a remote attacker to bypass authentication controls, enabling the execution of arbitrary flows and the retrieval of sensitive information. The vulnerability stems from improper authentication handling and is related to CWE‑287. This could lead to unauthorized code execution or data exposure within the application.
Affected Systems
The impacted product is IBM Langflow OSS. Versions affected range from 1.0.0 up to and including 1.11.1. All installations of these releases are vulnerable until patched to 1.11.2.
Risk and Exploitability
With a CVSS score of 8.2 the vulnerability is considered high risk. The EPSS metric is not available, so the exploitation probability cannot be quantified, and it is not listed in the CISA KEV catalog. However, the flaw can be exploited remotely without authentication, and an attacker only needs access to the web interface to trigger unsupported flow execution. Because the attack vector is external, organizations should treat it with high urgency.
OpenCVE Enrichment