Impact
IBM Langflow OSS between versions 1.0.0 and 1.12.2 contains an injection flaw that allows a remote authenticated attacker to execute arbitrary code. The vulnerability arises from improper neutralization of special elements in code that are interpreted by the runtime, leading to a sandbox escape. Because of this flaw a malicious user can compromise the entire system and gain full control, representing a high‑confidence remote code execution risk consistent with CWE‑94.
Affected Systems
Affected systems are IBM Langflow OSS installations running any of the versions listed from 1.0.0 up to 1.12.2 inclusive. The product includes the open source stack that is widely used for workflow orchestration. The only version that includes the fix is 1.12.3, which was released after the identified issue was published.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity impact, yet the EPSS score is not available so exact exploitation likelihood cannot be measured. Since the flaw requires the attacker to be authenticated, the attack vector is remote but limited to users who already have valid credentials. The issue is not present in the CISA KEV list, but it should still be treated as critical given the remote code execution potential. Organizations should act immediately to apply the fix or otherwise mitigate the risk.
OpenCVE Enrichment