Impact
The vulnerability exists in IBM Langflow OSS versions 1.0.0 through 1.10.0 where the webhook authentication logic incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False, which is the default. This flaw permits any unauthenticated user who knows a flow's UUID to trigger the execution of that flow on the target system, potentially allowing a remote attacker to run arbitrary code as if they were the owner. The primary impact is therefore Remote Code Execution, with full compromise of confidentiality, integrity, and availability for the affected instance.
Affected Systems
IBM Langflow OSS is the affected product. Versions 1.0.0 up to and including 1.10.0 are vulnerable. Users running these baseline releases are at risk unless the configuration is modified or the software is upgraded.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score is below 1%, suggesting that exploitation attempts are currently rare or not observed, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector is remote: an attacker who discovers a flow UUID can trigger the flow from an external network without authentication, exploiting the default configuration to gain arbitrary code execution.
OpenCVE Enrichment