Impact
IBM Langflow OSS versions 1.0.0 through 1.11.1 contain a namespace collision flaw that can allow a remote attacker to bypass authentication, traverse directory paths, authorize unintended actions, and perform server‑side request forgery. The vulnerability can result in viewing sensitive data and injecting unauthorized messages, compromising the confidentiality and control of the application.
Affected Systems
User deployments of IBM Langflow OSS that are running any version from 1.0.0 up through and including 1.11.1 are affected. The recommended fixed release is Langflow OSS 1.11.2.
Risk and Exploitability
The flaw scores a CVSS of 8.2, indicating substantial impact. Because the EPSS is not published, exploitation likelihood is unknown, but the attack vector is clearly remote, requiring only access to the exposed web interface or API. The vulnerability is not listed in CISA’s KEV catalog, but the combined factors of authentication bypass and potential data leakage make it a high‑risk issue.
OpenCVE Enrichment