Impact
Insecure deserialization occurs in IBM Langflow OSS 1.0.0 through 1.10.0 when Redis is used as a cache backend. The weakness (CWE-502) permits malicious data to be deserialized, allowing an attacker to execute arbitrary code with the application's full privileges. This results in complete compromise of secrets, data, and overall system integrity.
Affected Systems
Affected products are IBM Langflow OSS, specifically all releases from 1.0.0 up to and including 1.10.0. These versions are documented in the vendor’s product listings and the advisory notes that the vulnerability exists in that entire range.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. While a concrete EPSS score is not available, the lack of a recorded EPSS does not diminish the risk; attackers bearing access to the Redis instance can exploit the flaw without additional prerequisites. The vulnerability is not yet listed in CISA’s KEV catalog, but the combination of a high CVSS and the need for only Redis connectivity makes exploitation likely on exposed or compromised Redis hosts. Once exploited, the attacker gains full application control.
OpenCVE Enrichment