CyberRota Analysis
AI-GeneratedIBM Langflow OSS versions 1.0.0 to 1.10.0 are vulnerable to unauthenticated account creation, allowing attackers to generate unlimited user accounts. If the deployment option NEW_USER_IS_ACTIVE is enabled, these accounts become immediately active, enabling unauthorized access to remote code execution endpoints without requiring additional authentication. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created accounts are immediately active and can authenticate to reach RCE endpoints, bypassing the need for AUTO_LOGIN.
Related CVEs
Other vulnerabilities affecting the same vendor(s)