Impact
The vulnerability arises when IBM Langflow OSS interprets untrusted input in its Model Context Protocol features, allowing hackers to circumvent localhost‑only restrictions. Remote authenticated attackers can use this flaw to write arbitrary MCP server configurations to IDE configuration files on the host. This can result in the execution of malicious code or other privilege‑escalating actions, effectively granting attackers full control of the system. The weakness is categorized as insecure permission checks (CWE‑807).
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.10.3 are affected. Earlier releases beyond 1.10.3 have been patched; no other IBM products or languages are impacted per the CNA data.
Risk and Exploitability
The flaw carries a high severity CVSS score of 8.5 and has no publicly available EPSS estimate. It does not appear on the CISA Known Exploited Vulnerabilities list, suggesting no large‑scale active exploitation. Attackers must be authenticated, but once logged in they can bypass the intended access controls and write configuration files across the network, providing a clear path to remote code execution. The lack of in‑depth monitoring or key restrictions makes exploitation straightforward for any compromised account.
OpenCVE Enrichment