Impact
The vulnerability is a remote code execution flaw caused by improper enforcement of security restrictions on the A2A public endpoint of IBM Langflow OSS. An attacker can send specially crafted input that bypasses the intended code‑execution policy, allowing execution of arbitrary code within the hosting environment. Affected systems
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.11.1 are affected. The vulnerability exists in the A2A public endpoint across these releases, and no later version is known to be impacted. Risk and exploitability
Risk and Exploitability
The CVSS score of 9.8 indicates a critical risk with high impact and full remote attack vectors. The EPSS score is not available, so the exact probability cannot be quantified, but the absence of a KEV listing suggests the vulnerability has not yet been widely exploited. The attack vector is inferred to be remote through the A2A public API, requiring the ability to send crafted requests to the endpoint. Once exploited, an attacker could execute arbitrary code on the host, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment