Impact
IBM's Langflow OSS versions 1.0.0 through 1.12.2 contain an improper authorization flaw identified as CWE‑639 that permits an authenticated user to access data reserved for other roles. The vulnerability can lead to unauthorized disclosure of sensitive data, compromising confidentiality and potentially affecting data integrity. An attacker who can authenticate to the application can retrieve data that should be restricted.
Affected Systems
The vulnerable product is IBM Langflow OSS, specifically versions 1.0.0 through 1.12.2.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity. The EPSS score is not available, so the exact probability of exploitation cannot be quantified; however the vulnerability is not listed in CISA's KEV catalog, implying no known public exploitation. The attack requires authentication, so the attacker must possess valid credentials or succeed in credential compromise. Once authenticated, the attacker can use normal application APIs or interfaces to read data beyond their authorization level. The lack of further vetting mechanisms increases the risk that an attacker can obtain sensitive information after authentication.
OpenCVE Enrichment