CyberRota Analysis
AI-GeneratedIBM Langflow OSS versions 1.0.0 to 1.11.5 are vulnerable to remote authenticated attacks that exploit insufficient session expiration of API keys after user deactivation, potentially allowing attackers to execute flows and access sensitive information. Organizations using these versions should prioritize remediation to mitigate the risk of unauthorized access and data exposure. Immediate action is recommended for those managing sensitive data or relying on API integrations within their workflows.
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.