Impact
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a flaw that allows an attacker to inject arbitrary OS commands. The vulnerability results used in an OS command and can lead to full remote code execution. If exploited, an attacker could gain control of the host, read or modify data, and disrupt services. The impact covers confidentiality, integrity, and availability of the affected system.
Affected Systems
The affected product is IBM Langflow OSS, specifically all releases from 1.0.0 up to and including 1.11.5. The patched version is 1.11.6, which fix the command injection flaw. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 9.8 classifies this vulnerability as critical. The EPSS score is not available, but the severity indicates a high likelihood of exploitation in realistic attack scenarios. The vulnerability is not listed in the CISA KEV catalog at this time. Attack vectors are remote, as an attacker can exploit the flaw through the application’s interface without any special privileges. Once a crafted request is sent, the application will execute the supplied command and return the result, providing full command execution capabilities.
OpenCVE Enrichment