Impact
IBM Langflow OSS versions 1.0.0 through 1.11.2 contain a server‑side request forgery flaw that permits a remote attacker to provide malformed or intentionally crafted URLs, which the application forwards without proper validation, enabling the attacker to access internal resources and retrieve sensitive information.
Affected Systems
The affected product is IBM Langflow OSS. Versions from 1.0.0 up to and including 1.11.2 are susceptible, as indicated by the documented CPE strings and the vendor's advisory.
Risk and Exploitability
The flaw carries a CVSS score of 8.6, indicating a high potential impact. The EPSS score is not provided, so the likelihood of exploitation remains uncertain, and the vulnerability is not listed in CISA's KEV catalog. Attackers can trigger the SSRF by supplying malicious URLs via any input channel that the application accepts; no explicit prerequisite such as local privileges is mentioned in the advisory, making it inferred that the attack can be performed by any entity with access to the relevant interface, an assumption made based on typical SSRF patterns.
OpenCVE Enrichment