Impact
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a flaw in the apply_tweaks() function that allows authenticated users to override component parameters at runtime via the API. The absence of proper filtering for user‑supplied parameters could enable an attacker to inject malicious payloads, potentially resulting in arbitrary code execution or other severe system compromise. The weakness is identified as CWE-94 and is described as a parameter injection vulnerability.
Affected Systems
IBM Langflow OSS 1.0.0 through 1.10.0 are impacted. IBM recommends upgrading to version 1.10.1, which includes the required patch to the parameter filtering mechanism.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. Because the vulnerability requires authenticated access, attackers need valid credentials to exploit it. The vulnerability is not listed in the CISA KEV catalog, meaning it has not yet been tied to active exploitation campaigns. Nonetheless, the high severity and potential for Remote Code Execution warrant prompt remediation.
OpenCVE Enrichment