Impact
IBM Langflow OSS implements URL handling in several components without robust validation, creating a server‑side request forgery (SSRF) weakness identified as CWE‑918. By crafting requests that include arbitrary URLs, a remote authenticated attacker can instruct the application to contact internal or privileged services and retrieve sensitive information, potentially compromising confidentiality and integrity within the infrastructure. Based on the description, it is inferred that the vulnerability allows the attacker to direct the Langflow process to fetch arbitrary resources from a wide range of internal or external targets.
Affected Systems
The flaw exists in IBM Langflow OSS releases from version 1.0.0 up to 1.11.2. IBM strongly recommends upgrading to 1.11.3 to remediate the issue. No other vendors or product lines are currently reported to be affected.
Risk and Exploitability
The CVSS score of 5 denotes a moderate risk. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated to the application; the attack surface resides in the broker or API endpoints that forward user‑supplied URLs. Based on the description, it is inferred that no confirmed exploitation has been publicly reported, so the likelihood remains theoretical until an exploit is demonstrated.
OpenCVE Enrichment