Impact
The vulnerability arises from incomplete validation of user‑supplied code during component generation, validation, and custom component handling, allowing an attacker to inject and execute arbitrary code on the system. The flaw is a classic code injection weakness (CWE‑94) that enables full compromise of confidentiality, integrity, and availability if exploited.
Affected Systems
IBM Langflow OSS is affected in all releases from version 1.0.0 through 1.10.3. The affected CPEs include cpe:2.3:a:ibm:langflow_oss:1.0.0 and cpe:2.3:a:ibm:langflow_oss:1.10.3. IBM recommends updating to version 1.11.0 or newer.
Risk and Exploitability
The CVSS score of 8.8 classifies the weakness as high severity, and the security analyst should treat it with priority. Although the EPSS score is not available, the lack of a KEV listing does not reduce the risk of an attacker targeting this widespread platform. The likely attack path is remote: an attacker can send malicious code through the exposed component creation API or web interface, bypassing input checks and causing arbitrary code execution on the host.
OpenCVE Enrichment