Impact
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain an input‑validation flaw that allows an attacker to bypass the component type check when defining flow nodes. Submitting a flow with a missing or empty component type field can enable execution of arbitrary code on the host running the application. This flaw is classified as CWE‑20 and results in a high‑severity remote code execution vulnerability.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.10.0 are affected. Users of these versions, including the standard OSS distribution, should update promptly. The product is commonly used in data‑processing pipelines that rely on customizable flow definitions.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating a critical severity; the EPSS score is not available, so the probability of exploitation cannot be assessed from EPSS. It is not listed in the CISA KEV catalog. The likely attack vector is remote exploitation through the flow definition interface; an attacker with the ability to submit a flow that includes a missing or empty component type field can trigger the flaw and run arbitrary code on the host. The critical score and lack of mitigations underscore the need for immediate remediation.
OpenCVE Enrichment