Impact
IBM’s Langflow OSS contains a code injection flaw caused by improper neutralization of special elements used in an OS command. An attacker with valid credentials can supply crafted input that is passed directly to the operating system, allowing arbitrary code execution on the host system. The vulnerability originates from insufficient input validation and results in high impact on confidentiality, integrity, and availability of the affected systems.
Affected Systems
The flaw is present in IBM Langflow OSS versions 1.0.0 through 1.12.2, including the 1.12.2 release. All installations of these versions that expose endpoints or interfaces capable of evaluating user‑supplied data for OS command construction are affected. Upgrading to the released 1.12.3 release removes the vulnerability.
Risk and Exploitability
The CVSS score of 8.8 categorizes this as a high‑severity issue. The EPSS score is not available, but the lack of public exploitation reports does not diminish the potential for use by a skilled adversary who has access to authenticated accounts. Because the vulnerability requires authentication, internal actors or compromised credentials pose a significant risk. The vulnerability is not listed in CISA’s KEV catalog, but the high severity and the nature of the flaw warrant urgent remediation.
OpenCVE Enrichment