Impact
This vulnerability allows an attacker to execute arbitrary code on a Langflow OSS server by leveraging the component generation, validation, and custom component handling logic. The flaw is triggered through two HTTP requests and does not require any authentication, meaning anyone on the internet can abuse it. As a result, an attacker could run arbitrary programs, modify data, or take full control of the affected system, compromising confidentiality, integrity, and availability.
Affected Systems
The flaw affects IBM Langflow OSS from version 1.0.0 up to and including 1.10.3. Users running these releases – the open‑source edition of Langflow – are at risk and should confirm whether their deployment falls within this range.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability is considered high severity. The EPSS score is not available, so the current exploit likelihood cannot be quantified, but the attack conditions are simple – any remote user can craft the required HTTP traffic – and the flaw is listed as not in the CISA KEV catalog. Attack can exploit the server from outside, gaining full execution privileges, and can carry out the exploit with no prior access or credentials. The ease of exploitation and broad access scope make this a high‑risk threat.
OpenCVE Enrichment