IBM Langflow OSS: Multiple Vulnerabilities Fixed (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- RCE via unsafe deserialization and MCP config
- SSRF and path traversal in API components
- Privilege escalation and token theft possible
"IBM patched vulnerabilities in Langflow OSS 1.0.0 to 1.10.0, including RCE, SSRF, path traversal, privilege escalation. Unauthenticated attackers can obtain superuser tokens."
no comments yet.