Impact
IBM Langflow OSS versions 1.0.0 through 1.11.5 allow a remote authenticated attacker to execute arbitrary Python code when adding or modifying custom components in stored flows. The improper authorization check bypasses user privileges, enabling full code execution on the host and compromising confidentiality, integrity, and availability. The weakness corresponds to CWE-862, an Authorization Bypass Through User-Controlled Input.
Affected Systems
The vulnerability affects IBM Langflow OSS, specifically all releases from 1.0.0 up through 1.11.5. The affected distribution is available through the Open Source Software (OSS) channel and includes the Python package langflow.
Risk and Exploitability
The CVSS score of 8.8 indicates a high‑severity risk. The EPSS score is not available, so current exploitation probability cannot be quantified from that metric. The vulnerability is not listed in the CISA KEV catalog. Attackers who are authenticated can upload a malicious flow containing custom component code and trigger execution on the target. The likely attack vector is via the web interface or API where authenticated users can create or edit flows.
OpenCVE Enrichment