Impact
IBM Langflow OSS versions 1.0.0 through 1.12.2 suffer from an OS command injection flaw (CWE‑94). When an authenticated user supplies specially crafted input, the application fails to neutralize special elements, enabling execution of arbitrary operating‑system commands. This gives a remote attacker the full platform‑level capabilities of the machine hosting the application, potentially compromising confidentiality, integrity, and availability.
Affected Systems
IBM Langflow OSS (open‑source edition) is affected in versions 1.0.0 to 1.12.2. The security advisory recommends upgrading to version 1.12.3 or later to remediate the flaw. Users running earlier releases are at risk.
Risk and Exploitability
With a CVSS score of 8.1 the vulnerability is classified as High severity. No EPSS score is currently published, so exploitation probability cannot be quantified. It is not listed in CISA KEV, suggesting no known widespread exploitation yet. The flaw requires that the attacker already have authenticated access to the application, but once authenticated they can run arbitrary OS commands. Attackers can lever this to elevate privileges, compromise the host, or pivot to other systems. No additional conditions are listed, implying that the presence of standard user credentials is sufficient for exploitation.
OpenCVE Enrichment