Impact
IBM Langflow OSS versions 1.0.0 through 1.12.2 contain an OS command injection flaw caused by improper neutralization of special elements used in an operating‑system command. An attacker who can supply these elements can cause the application to execute arbitrary commands on the host machine, allowing full compromise of the affected system. The weakness is classified as CWE‑94, indicating unsanitized user input that is passed to an OS command executor.
Affected Systems
IBM Langflow OSS, specifically versions 1.0.0 up to and including 1.12.2, are impacted. Any installation of these releases running in an environment where the application’s command execution context is exposed to network input is vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating critical severity. The EPSS score is not available, and the issue is not listed in CISAs KEV catalog, but the high CVSS suggests it is a prime target for exploitation. An attacker can exploit the flaw remotely, without requiring prior authentication, by sending specially crafted input that incorporates dangerous command constructs. The lack of unit tests or input validation in the affected code paths makes exploitation straightforward for a skilled threat actor.
OpenCVE Enrichment