CyberRota Analysis
AI-GeneratedIBM Langflow OSS versions 1.0.0 through 1.10.3 are vulnerable due to inadequate validation of ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, enabling authenticated users to inject arbitrary graph data into a shared cache. This flaw could lead to cross-user cache pollution, unauthorized execution of workflows, or potential denial of service. Organizations using affected versions should prioritize remediation to mitigate risks associated with unauthorized data manipulation and service disruption.
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache pollution, unauthorized workflow execution, or denial of service.
Related CVEs
Other vulnerabilities affecting the same vendor(s)