Impact
IBM Langflow OSS versions 1.0.0 through 1.11.5 are affected by a server‑side request forgery flaw caused by absent egress validation on server‑side URL fetches. The weakness allows a remote authenticated attacker to supply arbitrary URLs that the application will query, potentially exposing internal services, application data, or sensitive external resources. The identified CWE is 918, which categorizes it as a server‑side request forgery vulnerability.
Affected Systems
The vulnerable products are IBM Langflow OSS, specifically releases from 1.0.0 up to and including 1.11.5. Recent updates release protection in version 1.11.6, which should be used where possible.
Risk and Exploitability
The CVSS score of 5 indicates moderate severity. EPSS data is not available CISA's KEV catalogue. Because the flaw requires the attacker to possess valid credentials to supply the malicious URL, the attack vector is limited to authenticated users but still enables endpoints.
OpenCVE Enrichment