Impact
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain an incomplete environment variable blocklist that allows an authenticated user to execute arbitrary code. The flaw is a classic code injection issue and is identified as CWE-94. Because the code is executed in the context of the application, an attacker who can authenticate can run any code, potentially leading to a complete compromise of the host system.
Affected Systems
The affected product is IBM Langflow OSS. All releases from 1.0.0 to 1.11.5 are impacted. Users who have not upgraded to version 1.11.6 are at risk. The product is normally deployed in open‑source Python environments.
Risk and Exploitability
The CVSS score of 8.8 classifies this vulnerability as high severity. There is no EPSS estimate available, but the lack of an estimate does not reduce the risk. The flaw requires authenticated access and does not rely on other environmental prerequisites. Consequently, any user who obtains valid credentials can exploit the flaw easily. The vulnerability is not listed in the CISA KEV catalog, yet the high severity rating and authentication requirement make it a priority for organizations that expose Langflow OSS to external traffic.
OpenCVE Enrichment