Impact
IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to remote code execution if an attacker is authenticated and can create or modify flow display names. The vulnerability stems from improper neutralization of special characters, allowing attacker‑supplied code to be executed on the server. The impact is that a compromised account could run arbitrary commands with the privileges of the Langflow service.
Affected Systems
The affected product is IBM Langflow OSS, specifically versions 1.0.0 to 1.11.5. These versions are listed on PyPI under the langflow package and are commonly installed in open‑source deployments that expose flow‑definition interfaces to users.
Risk and Exploitability
The CVSS score of 8.8 classifies this as High severity. The EPSS score is not available, and the vulnerability has not been listed in CISA KEV. The attack requires remote authenticated access, and the absence of execution guards means any attacker who can manipulate flow names may run code on the host. Given the high severity and lack of mitigations in affected releases, the risk to any system running an unpatched version is significant.
OpenCVE Enrichment