Impact
The vulnerability in IBM Langflow OSS permits a server‑side request forgery because the SSRF protection enforcement is incomplete and ineffective. This flaw enables an attacker to make the server issue arbitrary HTTP requests. Based on this description, it is inferred that the attacker could target internal or external resources potentially leading to data exposure or further exploitation.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected. These releases lack the required SSRF safeguards mentioned in the vendor’s documentation. Only the upgrade to version 1.11.0 or newer provides the proper protection.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity flaw. No EPSS score is available, so the probability of exploitation remains uncertain. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves submitting a crafted request to the provider validation or API request functions, where the target URL is not adequately validated. Based on the description, it is inferred that an attacker could supply arbitrary URLs to trigger the SSRF behavior.
OpenCVE Enrichment