Impact
The vulnerability exists in IBM Langflow OSS 1.0.0 through 1.11.5. An attacker who can provide custom component source code can bypass the static security scanner by crafting an annotated class‑body assignment that resolves to a dangerous callable. Because the resolution path is not checked against a blocklist, the component can reach the runtime execution path and trigger arbitrary operating‑system commands on the server with the privileges of the running service. This represents a complete compromise of confidentiality, integrity, and availability.
Affected Systems
IBM Langflow OSS, versions 1.0.0 to 1.11.5, deployed in environments that allow user submission of component code. All deployments of these releases are vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 8.8 categorizes the flaw as High severity. The EPSS score is not available, so the precise likelihood of exploitation cannot be quantified; however, the absence of a KEV listing does not mitigate the risk. The attack vector is remote, since the attacker only needs to submit malicious component code, and no additional privileges are required beyond what the Langflow service runs with. Any unattended or permissive installation that accepts untrusted code is therefore at elevated risk of arbitrary code execution.
OpenCVE Enrichment