CyberRota Analysis
AI-GeneratedIBM Langflow versions 1.0.0 to 1.10.3 are vulnerable to a remote authenticated attack that allows bypassing localhost-only restrictions, enabling attackers to write arbitrary MCP server configurations to IDE configuration files on the host system. This could lead to unauthorized access and manipulation of the system's configuration, potentially compromising its integrity and security. Organizations using affected versions should prioritize patching this vulnerability to mitigate the risk of exploitation.
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system.
Related CVEs
Other vulnerabilities affecting the same vendor(s)