PT-2026-60866 · Ibm · Langflow Oss
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Langflow OSS versions 1.0.0 through 1.10.0
Description
A flaw in the webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the
WEBHOOK AUTH ENABLE configuration is set to False, which is the default setting. A remote attacker who knows a flow's UUID can execute it as the owner, potentially leading to Remote Code Execution (RCE), a state where an attacker can execute arbitrary commands on the host machine.Recommendations
Update IBM Langflow OSS to version 1.10.1.
Enable webhook authentication by setting
WEBHOOK AUTH ENABLE to True.
Avoid exposing builder APIs.Fix
RCE
DoS
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langflow Oss