Impact
IBM Langflow OSS versions 1.0.0 through 1.12.2 contain an injection vulnerability that allows a remote authenticated attacker to execute arbitrary code due to improper control of code generation. The flaw stems from CWE-94, which describes malicious code injection when an attacker influences input that is interpreted or compiled. If exploited, the attacker could gain full control over the application, compromising confidentiality, integrity and availability of the server where the service runs.
Affected Systems
The affected system is IBM Langflow OSS, specifically all releases from 1.0.0 up to and including 1.12.2. The vendor’s CPE entries list these builds and IBM recommends upgrading to version 1.12.3 to address the flaw.
Risk and Exploitability
The CVSS base score of 8.1 indicates high severity, and the EPSS score is not available, so objective exploitation probability cannot be quantified. The vulnerability is listed in no KEV catalog, implying no known exploitation in the wild; however, the flaw requires an attacker to be authenticated to the instance, meaning compromised credentials or a brute‑forced login could lead to arbitrary code execution. Remote code execution of this nature represents a critical threat to any affected system.
OpenCVE Enrichment