Impact
The vulnerability in IBM Langflow OSS arises from improper neutralization of special elements used in code, enabling a remote authenticated attacker to execute arbitrary code. The weakness corresponds to scripting code injection (CWE‑94). When exploited, the attacker can run arbitrary commands or scripts within the application context, potentially gaining full system compromise and exposing confidential data.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.12.2 are susceptible, as stated by the CNA. The affected product is IBM's open‑source implementation of Langflow, used to build and run code‑flow applications. Only those deployments that have not yet upgraded to 1.12.3 remain vulnerable.
Risk and Exploitability
The CVSS score of 7.5 classifies this flaw as high severity. No EPSS score is available, so the precise exploitation probability cannot be quantified, but the flaw is not listed in the CISA KEV catalog. Attack requires a valid authenticated session to the Langflow OSS instance; once authenticated, the attacker can supply malicious code input that bypasses sanitization, leading to remote code execution. Given the high CVSS, the risk is significant and remediation is strongly recommended.
OpenCVE Enrichment