Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6jrp-2cpp-fpm4

Опубликовано: 17 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authenticated user to execute arbitrary system commands with the full privileges of the Langflow server process.

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authenticated user to execute arbitrary system commands with the full privileges of the Langflow server process.

EPSS

Процентиль: 37%
0.00458
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.9
nvd
16 дней назад

IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's built-in exec() function without sandboxing, input validation, or privilege restrictions, enabling any authenticated user to execute arbitrary system commands with the full privileges of the Langflow server process.

EPSS

Процентиль: 37%
0.00458
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-94