Impact
The vulnerability is a dependency‑confusion flaw that allows a remote attacker to execute arbitrary code within the IBM Langflow OSS service. By manipulating the dependency name resolution process, the attacker can cause the application to import an untrusted module, leading to full control of the host and compromising confidentiality, integrity, and availability. The weakness is formalized as CWE‑440, which describes risks associated with ambiguous or conflicting dependency names.
Affected Systems
The affected product is IBM Langflow OSS. Versions from 1.0.0 up to and including 1.12.2 are impacted. The vendor recommends upgrading to version 1.12.3 to eliminate the issue. Earlier releases of Langflow OSS that do not include the patch remain vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, while the EPSS score is not provided, leaving the precise exploitation likelihood uncertain. Because the vulnerability is no longer listed in the CISA KEV catalog, there is no current evidence of active exploitation, but the remote nature and the ability to run arbitrary code make it a high-risk target. Attackers could trigger the flaw by publishing a malicious dependency that conflicts with the expected one, a scenario which requires no special privileged credentials and can be performed over the public network.
OpenCVE Enrichment