Impact
An incomplete blocklist in IBM Langflow OSS’s code security scanner allows a malicious actor to inject and execute arbitrary code. The flaw can be exploited to run code with the privileges of the application, granting full control over the host environment, compromising data integrity and confidentiality, and potentially allowing further lateral movement within the network. The underlying weakness is a code injection problem identified as CWE‑94.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.12.2 are vulnerable. Upgrading to version 1.12.3 removes the flaw, as released by IBM. The affected products are under the IBM vendor name and the OS‑agnostic Langflow OSS component.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity. While the EPSS score is not available, the lack of a KEV listing suggests no publicly known exploits yet; however, the nature of the flaw implies a remote code execution attack vector that could be accessed through any exposed API or interface that triggers the scanner. Based on the description, the likely attack vector is remote, and an attacker could possibly trigger the injection by sending specially crafted input to the application.
OpenCVE Enrichment