Impact
IBM Langflow OSS 1.0.0 through 1.11.2 contains an unvalidated pathname in its file‑processing components that allows a remote authenticated attacker to delete or write to arbitrary local files or directories. The flaw stems from improper limitation of the path to a restricted directory, enabling direct file system manipulation. This could jeopardize confidentiality, integrity, and availability of the system, and may allow widespread data loss or the introduction of malicious files.
Affected Systems
The vulnerability affects IBM’s Langflow OSS product. All releases from version 1.0.0 up to and including 1.11.2 are impacted. The official fix is included in version 1.11.3, which is also available via PyPI.
Risk and Exploitability
The CVSS score of 8.1 classifies the issue as high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation in the wild at this time. The attack requires remote authenticated access to the application, after which the attacker can specify an arbitrary file path to cause deletion or overwrite. Due to the lack of a current exploit, the risk is theoretical but significant given the potential for destructive file operations.
OpenCVE Enrichment