CyberRota Analysis
AI-GeneratedIBM Langflow OSS versions 1.0.0 to 1.11.1 are vulnerable to a critical flaw that enables authenticated attackers to execute arbitrary operating system commands by manipulating flow configurations. This vulnerability allows privilege escalation from an authenticated user to arbitrary command execution at the server process level, circumventing existing security controls. Organizations using affected versions should prioritize immediate remediation to mitigate the risk of exploitation.
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing the LANGFLOW_ALLOW_CUSTOM_COMPONENTS=false policy control.
Related CVEs
Other vulnerabilities affecting the same vendor(s)