AI analysis
IBM Langflow OSS versions 1.0.0 through 1.12.2 do not properly neutralize special elements used in code (CWE-94), so a remote authenticated attacker can escape the execution sandbox and run arbitrary code. The issue is reachable over the network with low privileges and no user interaction, and successful exploitation can fully compromise confidentiality, integrity, and availability of the affected process. Organizations running Langflow OSS in that version range are affected, particularly where instances are reachable beyond a tightly controlled network. IBM has announced patches for multiple Langflow OSS flaws that include remote code execution, but this CVE is not in CISA's Known Exploited Vulnerabilities catalog. No public proof-of-concept is known, and there is no confirmed in-the-wild exploitation.
What to do: Upgrade IBM Langflow OSS to a release newer than 1.12.2 as identified in IBM's security advisory, and take 1.0.0 through 1.12.2 instances off untrusted networks until they are patched. Until then, restrict access to trusted authenticated users, apply least privilege, and review logs for unexpected code execution or sandbox escapes. Confirm the installed build against IBM's fixed-release guidance rather than assuming a specific patch version.
Affected
| IBM Langflow OSS | 1.0.0 through 1.12.2 |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code, resulting in a sandbox escape.