Impact
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a flaw that lets an unauthenticated attacker execute arbitrary code and alter or retrieve chat session data via publicly shared MCP project endpoints. The vulnerability stems from insufficient enforcement of public‑flow security restrictions and inadequate isolation of user sessions, allowing an attacker to inject code that runs within the application environment. This can lead to full compromise of the affected system, including data exfiltration, persistence, and further lateral movement.
Affected Systems
IBM Langflow OSS is the affected product, specifically versions 1.0.0 up to and including 1.11.5. The issue applies to installations that expose MCP project endpoints publicly, which are commonly used to share flow definitions with other users.
Risk and Exploitability
The CVSS score of 9.8 classifies this flaw as critical, indicating a high likelihood of a successful attack if the vulnerability is exploited. While the EPSS score is not available, the absence of a KEV listing does not diminish the potential for exploitation; many similar remote code execution flaws are actively targeted in the wild. The attacker can reach the vulnerable endpoint over the network without authentication, making the attack surface broad and the risk for any exposed deployment significant. Prompt remediation is strongly advised to mitigate both confidentiality, integrity, and availability risks.
OpenCVE Enrichment