Impact
IBM Langflow OSS versions 1.0.0 through 1.12.2 contain an information‑exposure flaw (CWE‑200) that allows a remote authenticated attacker to retrieve sensitive data that should not be publicly accessible. The vulnerability permits the attacker to access data beyond the intended authorization boundaries, potentially compromising user privacy and system integrity.
Affected Systems
The affected product is IBM Langflow OSS, with all releases from version 1.0.0 up to and including 1.12.2 impacted. The latest released version at the time of the advisory is 1.12.2, and upgrading to 1.12.3 is recommended.
Risk and Exploitability
The CVSS score of 7.7 reflects a high severity rating for information‑exposure vulnerabilities. The EPSS score is not available, but the KEV status indicates it is not currently listed in CISA’s Known Exploited Vulnerabilities catalog. The attack vector is remote and requires authentication; an attacker with valid credentials can exploit the flaw to access confidential data. No additional prerequisites beyond authentication are noted in the advisory.
OpenCVE Enrichment