Impact
An authenticated non‑administrative user can construct a flow that includes an MCP Tools component configured with a local stdio subprocess transport, bypassing the Langflow server‑side controls designed to restrain such execution. This flaw gives the attacker the ability to run arbitrary operating system commands at the privileges of the application process, exposing sensitive data such as environment credentials, modifying the file system, and enabling lateral movement to other services on the host.
Affected Systems
IBM Langflow OSS, versions 1.0.0 through 1.11.5 are vulnerable. The patched release is 1.11.6.
Risk and Exploitability
The CVSS score of 8.8 classifies this vulnerability as high severity. EPSS data is not provided, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication as a non‑administrative user, so the attack vector is internal. Once authenticated, the attacker can execute arbitrary commands on the host, compromising integrity and availability.
OpenCVE Enrichment