CyberRota Analysis
AI-GeneratedIBM Langflow OSS versions 1.0.0 to 1.10.1 are vulnerable to unauthorized access, allowing attackers to retrieve private vector documents from other users by manipulating flow configurations. This exploitation can lead to data leakage and unauthorized modification of shared collections, posing significant risks to user privacy and data integrity. Organizations using affected versions should prioritize immediate remediation to safeguard sensitive information and maintain operational security.
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victim's flow. Additionally, the attacker can pollute the victim's collection by inserting their own documents into the shared namespace.
Related CVEs
Other vulnerabilities affecting the same vendor(s)