AI analysis
IBM Langflow OSS versions 1.0.0 through 1.12.2 can allow a remote attacker to execute arbitrary code through a dependency-confusion issue classified as CWE-440 (expected behavior violation). The CVSS 3.1 vector is network-reachable with low complexity and no privileges required, but user interaction is required, so someone using an affected install must take an action that causes a malicious dependency to be resolved. Successful exploitation has high impact on confidentiality, integrity, and availability while scope stays unchanged (CVSS 8.8 high). Organizations running those Langflow OSS versions are affected. It is not listed in CISA KEV and no public proof-of-concept is known; IBM has been reported as patching multiple Langflow OSS flaws, including RCE issues, but this record does not name a fixed version.
What to do: Upgrade IBM Langflow OSS to a vendor-patched release outside 1.0.0 through 1.12.2, confirming the fixed version in IBM’s advisory before you install it. Until then, pin and verify package dependencies, use a trusted or private package index, and review recent installs for unexpected packages. No public exploit or CISA KEV listing is known, but unpatched installs should be treated as high risk.
Affected
| IBM Langflow OSS | 1.0.0 through 1.12.2 |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.