Impact
Missing URL validation on server‑side URL fetches in IBM Langflow OSS creates a classic SSRF flaw that permits a remote attacker to supply arbitrary URLs and cause the application to reach internal network resources. The attacker can exfiltrate sensitive data from the internal environment, such as database endpoints, configuration files or other services accessible only from within the network. This weakness is directly identified as CWE‑918 and can result in confidentiality compromise at the application or infrastructure level.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.11.5 are vulnerable because they lack the required egress validation. Version 1.11.6 incorporates the fix and should be deployed to any installations remaining on older releases.
Risk and Exploitability
The issue carries a CVSS score of 8.6, indicating high severity, and is not listed in the CISA KEV catalogue. The EPSS score is not available, but the lack of input validation suggests a straightforward attack path: a remote attacker crafts a request with a malicious URL and sends it to the vulnerable endpoint, causing the server to make an unexpected internal network call. Exploitation requires no special privileges on the target system.
OpenCVE Enrichment