Impact
The vulnerability allows an authenticated attacker to execute arbitrary code by exploiting improper control of code generation; this is a classic example of CWE‑94 and can lead to complete compromise of the running system.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.12.2 are affected by this flaw; upgrading to version 1.12.3 or later removes the vulnerability.
Risk and Exploitability
The issue carries a CVSS score of 8.5, indicating high severity, and no EPSS value is available. It is not listed in CISA KEV. The threat requires an authenticated user to trigger the code generation feature, implying a remote code execution scenario that could be abused by attackers who gain legitimate or stolen credentials. Organizations should treat this as a high‑risk vulnerability and act promptly.
OpenCVE Enrichment