Impact
The vulnerability allows an authenticated attacker to execute arbitrary code by exploiting a bypass in the flow build authorization logic. The flaw is identified as a code injection type weakness (CWE-94) and could give the attacker full control over the affected system.
Affected Systems
The affected product is IBM Langflow OSS, versions ranging from 1.0.0 up to 1.11.2 are vulnerable. Any installation of these releases in a networked environment is susceptible if the flow build endpoint is exposed.
Risk and Exploitability
The CVSS score of 8.8 marks this issue as high severity, and although the EPSS score is not available, the lack of a KEV listing does not diminish the risk. Exploitation requires authentication but the bypass allows the attacker to run arbitrary code through the flow build process, making it a direct threat to confidentiality, integrity, and availability of the impacted system.
OpenCVE Enrichment