Impact
An authenticated attacker can exploit a lack of validation on command‑line arguments in the MCP stdio server configuration of IBM Langflow OSS to execute arbitrary OS commands. This flaw aligns with command injection weaknesses and can compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
IBM Langflow OSS versions from 1.0.0 through 1.11.5 are affected. The issue is resolved in version 1.11.6, which IBM recommends installing without delay.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating a high severity. The flaw is not listed in the known widespread exploitation. The likely attack vector requires remote authenticated access to the MCP stdio server, and an attacker could leverage the flaw to run arbitrary commands once authenticated.
OpenCVE Enrichment