Impact
The vulnerability stems from incomplete security controls and missing execution guards in IBM Langflow OSS, allowing code injection during graph construction. An attacker can supply malicious input that is interpreted as executable code, giving the attacker full control over the host system. The flaw aligns with CWE-94, indicating a vulnerability to arbitrary code execution, with the provided CVSS score of 9.8 underscoring its critical severity.
Affected Systems
IBM Langflow OSS releases from version 1.0.0 through 1.11.5 are affected, including the 1.11.5 build referenced in the advisory. Users deploying these versions bear the risk of remote code execution if they accept externally constructed graphs.
Risk and Exploitability
The CVSS score of 9.8 classifies the issue as critical, and while an EPSS value is not available, the nature of the flaw—remote code execution via graph construction—suggests high likelihood of exploitation, especially when the affected API is exposed to untrusted inputs. The vulnerability is not currently listed in the CISA KEV catalog, but its severity warrants immediate attention.
OpenCVE Enrichment