Impact
IBM Langflow OSS versions 1.0.0 through 1.10.0 contain an arbitrary code execution flaw (CWE‑94). An attacker who can authenticate to the application can manipulate the database to elevate privileges to superuser, then launch arbitrary system commands with the application’s service permissions. This leads to full compromise of the host running the Langflow service.
Affected Systems
The vulnerability affects IBM Langflow OSS, specifically all releases from 1.0.0 up to and including 1.10.0.
Risk and Exploitability
The CVSS score for this issue is 9.9, indicating critical severity. The EPSS score is less than 1 %, meaning exploitation likelihood is low but still possible, especially in environments where database credentials are weak or exposed. The vulnerability is not listed in the CISA KEV catalog, so no known public exploits have been documented yet. The attack vector is inferred to be authenticated database manipulation within the application, allowing privileged escalation to superuser and subsequent execution of arbitrary system commands.
OpenCVE Enrichment