AI analysis
IBM Langflow OSS versions 1.0.0 through 1.12.2 contain an insecure deserialization flaw (CWE-502) in how cached values are handled. An attacker who already has the server secret and write access to Redis can submit a malicious serialized cache value; when the application later retrieves that value, deserialization can execute attacker-controlled code with the privileges of the Langflow service process. Successful exploitation yields remote code execution with high impact to confidentiality, integrity, and availability, though attack complexity is high and low privileges are required. Self-hosted Langflow OSS deployments in the affected version range are at risk. No public proof of concept is known and the issue is not in the CISA Known Exploited Vulnerabilities catalog, so exploitation in the wild is not known.
What to do: Upgrade IBM Langflow OSS to a release newer than 1.12.2 as soon as the vendor fix is available. Until then, restrict write access to Redis and protect the server secret so untrusted parties cannot inject cache entries, and treat any exposure of that secret or Redis as a possible code-execution event.
Affected
| IBM Langflow OSS | 1.0.0 through 1.12.2 |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow an attacker with access to the server secret and Redis write access to submit a malicious serialized cache value. When the value was retrieved, deserialization could have executed attacker-controlled code with the privileges of the service process.