Impact
IBM Langflow OSS contains an improper control of code generation flaw (CWE‑94) that can allow a remote authenticated attacker to execute arbitrary code. The vulnerability could enable the attacker to take full control of any host running the application, leading to loss of confidentiality, integrity, and availability, and the CVSS score of 8.8 reflects a high severity impact.
Affected Systems
The flaw exists in IBM Langflow OSS versions 1.0.0 through 1.12.2. All releases in that range expose the vulnerability; upgrading to 1.12.3 eliminates the issue.
Risk and Exploitability
The CVSS score of 8.8 indicates a serious risk. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly documented exploits yet. However, the flaw requires the attacker to authenticate, after which malicious code can be supplied and executed with the application’s privileges. Because of the high impact and the requirements for authenticated access, organizations that rely on these versions should prioritize patching.
OpenCVE Enrichment