Impact
IBM Langflow OSS is vulnerable to deserialization of untrusted data. An attacker who can write to the Redis cache and who knows the server secret can place a malicious serialized value. When the service later retrieves this value, deserialization executes attacker‑controlled code with the privileges of the service process, resulting in full remote code execution. The flaw directly compromises confidentiality, integrity, and availability of the system.
Affected Systems
The affected product is IBM Langflow OSS versions 1.0.0 through 1.12.2. IBM recommends upgrading to version 1.12.3 or later to eliminate the issue.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. Although the EPSS score is not available, the lack of listing in CISA KEV does not diminish the potential impact, especially given the required conditions of a server secret and Redis write permission. The attack vector is likely to be internal or authenticated remote, and an attacker with those privileges can achieve arbitrary code execution on the host.
OpenCVE Enrichment