Impact
The vulnerability is a Server‑Side Request Forgery (SSRF) caused by missing or bypassable URL validation in multiple components of IBM Langflow OSS. It allows a remote authenticated attacker to trigger requests to internal services and retrieve sensitive information. The weakness corresponds to CWE‑918.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.11.2 are affected. The vulnerability is present in the code base that parses and forwards user supplied URLs without adequate validation.
Risk and Exploitability
The CVSS score of 7.7 rates this flaw as high severity. No EPSS score is currently available, and the issue is not listed in the CISA KEV catalog. An attacker with valid credentials can exploit the flaw by supplying a malicious URL that targets internal endpoints, resulting in data disclosure. The exploit requires authentication, so it poses a significant risk to environments where credentials are leaked or intercepted.
OpenCVE Enrichment