Impact
IBM Langflow OSS versions 1.0.0 through 1.11.1 contain an improper authorization flaw that allows any remote authenticated user to execute and read another user’s private flow. The weakness, categorized as CWE-639, permits an attacker to bypass normal access controls and gain full control over the target user’s flows, potentially exposing sensitive data and enabling further malicious operations within the application.
Affected Systems
The affected product is IBM Langflow OSS, specifically the release line from 1.0.0 up to 1.11.1. Users running any of these versions should review the installation and verify the application version to determine if they are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4, indicating moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. An attacker would need to authenticate to the system first and then exploit the authorization bypass. While the exploitability is limited to authenticated users, the impact is significant due to the potential to execute or read confidential flows.
OpenCVE Enrichment