Impact
The vulnerability arises from improper input validation, which allows a remote authenticated user to execute arbitrary code on the server. Attackers can inject malicious payloads that are misinterpreted by the application and result in code execution. The type of weakness corresponds to CWE-693, indicating a failure to enforce adequate protection mechanisms.
Affected Systems
IBM Langflow OSS versions 1.0.0 through 1.12.2 are impacted. System administrators should verify whether their deployments run any of these releases and prepare to deploy the fixed release 1.12.3 or later.
Risk and Exploitability
With a CVSS score of 8.8, the severity is high. No EPSS score is available, and the vulnerability is not listed in CISA KEV, suggesting no confirmed widespread exploitation yet. However, because the flaw requires remote authentication, attackers who can obtain or guess valid credentials can leverage the vulnerability. Administrators should assume the risk of a successful exploit until the patch is applied.
OpenCVE Enrichment