Impact
IBM Langflow OSS versions 1.0.0 through 1.12.2 contain an improper access control flaw in the vertex result caching subsystem, classified as CWE-284. The flaw permits a remote attacker who has authenticated to the application to read sensitive information that is cached or to inject malicious data into the cache. This could lead to disclosure of confidential data or the execution of unintended operations within the application.
Affected Systems
All publicly available builds of IBM Langflow OSS from version 1.0.0 up to and including 1.12.2 are affected. The vulnerability is specific to the vertex result caching component within the Langflow OSS code base. No later releases beyond 1.12.2 are known to contain the flaw.
Risk and Exploitability
With a CVSS score of 8.3, the vulnerability is considered high severity. The EPSS score is not available, so there is no current estimate of how frequently this vulnerability is being exploited in the wild. Because the flaw requires an authenticated session, an attacker must first gain legitimate credentials before exploiting the weakness. The vulnerability is not currently listed in the CISA KEV catalog. Given the high CVSS score and the authentication requirement, the risk of exploitation is moderate to high for organizations that maintain user access to Langflow OSS.
OpenCVE Enrichment