Impact
The vulnerability in IBM Langflow OSS versions 1.0.0 through 1.11.1 permits an attacker who is authenticated as a flow user to embed a specially crafted value in the type field when saving a flow. This value is later used to build a wrapper flow that references it and causes the server to execute arbitrary operating system commands with the server process privileges. The result is a remote code execution that elevates an authenticated flow user to full OS‑level command execution, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false configuration that was intended to prevent custom component execution.
Affected Systems
The affected product is IBM Langflow OSS, specifically any release from 1.0.0 up to and including 1.11.1. Servers that run these versions and allow authenticated flow users to create or modify flows are vulnerable.
Risk and Exploitability
The CVSS score of 9.9 indicates critical severity. While the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the fact that only authenticated users can exploit it makes active monitoring and quick remediation essential to prevent privilege escalation to OS‑level execution.
OpenCVE Enrichment