Description
IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
- ibm / langflow_oss1.0.0 – 1.0.0
- ibm / langflow_oss1.10.0 – 1.10.0
- langflow / langflow1.0.0 – 1.10.1
References
Updated 28m ago · 8 sources