AI analysis
IBM Langflow OSS 1.0.0 through 1.12.2 has an incomplete blocklist in its code security scanner, which is a code-injection flaw (CWE-94). A remote attacker who already has low-privileged access can submit code the scanner fails to reject, so the server executes it. Exploitation gives high impact to confidentiality, integrity, and availability on the Langflow host (CVSS 3.1 8.8; network, low complexity, no user interaction, privileges required). Organizations running those Langflow OSS versions are affected, especially where the service is reachable by untrusted users. It is not in CISA KEV and no public proof-of-concept is known.
What to do: Upgrade IBM Langflow OSS to a vendor-patched release newer than 1.12.2 (the CVE data does not name the fixed build). Until that is deployed, do not expose the service to untrusted networks, restrict accounts that can author or run custom code, and review logs for unexpected code execution.
Affected
| IBM Langflow OSS | 1.0.0 through 1.12.2 |
Estimated exposure
moderate≈1,000–10,000 active deployments (order-of-magnitude estimate) — No install count or internet-scan total is in the CVE data. Langflow OSS is a widely used self-hosted LLM workflow builder rather than a mass consumer product, so a thousands-scale footprint of deployments is a plausible order-of-magnitude…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.