CyberRota Analysis
AI-GeneratedDocker-based MCP servers running IBM Langflow OSS versions 1.0.0 to 1.10.3 are vulnerable to exploitation by authenticated attackers, who can read, modify, or expose sensitive host files due to inadequate filtering of Docker volume-mount and device-mapping arguments. Organizations utilizing these versions should prioritize patching to mitigate the risk of data exposure and potential system compromise. Security teams and system administrators managing Docker environments should take immediate action to address this vulnerability.
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments.
Related CVEs
Other vulnerabilities affecting the same vendor(s)