Impact
The vulnerability arises from improper handling of language-model–generated Python code during component validation in IBM Langflow OSS. An authenticated user can trigger the execution of arbitrary code as the backend processes LLM-generated components before user approval, potentially enabling outbound network connections, filesystem modifications, or data exfiltration under the privileges of the backend process.
Affected Systems
Affected systems include IBM Langflow OSS version 1.0.0 up to 1.10.3. The flaw exists in the component generation, validation, and custom component handling modules of these releases. No other vendors or product lines are listed as impacted.
Risk and Exploitability
The CVSS score of 8.1 classifies the issue as High severity; however, the EPSS score is not available, making it unclear how frequently it is targeted. The vulnerability requires authenticated access, so the risk mainly concerns users with legitimate credentials or compromised accounts. The CNA has not catalogued it in KEV, suggesting no confirmed exploits yet. Until a patch is applied, the threat remains that an attacker could execute code with the capabilities of the Langflow backend.
OpenCVE Enrichment