Impact
This vulnerability exploits an incomplete deny-list in IBM Langflow OSS security scanner, allowing an authenticated user to inject and execute arbitrary code. The weakness is classified as CWE-78, reflecting insufficient validation of executable paths. Successful exploitation would give the attacker the same privileges as the Langflow process, potentially compromising system confidentiality and integrity.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.11.5, which are delivered through the "langflow_oss" Python package prior to the 1.11.6 release that contains the fix.
Risk and Exploitability
The CVSS score of 8.8 signals high severity. No EPSS data is available, but the risk remains significant because the vulnerability requires only authenticated access, a condition that attackers often satisfy in targeted attacks. The vulnerability is not listed in CISA’s KEV catalog, indicating that active exploitation has not yet been documented widely. Attacks would likely proceed via an API web interface that allows an authenticated user to supply code input to the security scanner.
OpenCVE Enrichment