IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
VTP deterministic threat9.9of 100 · CVSS excluded
VTP analyst assessment
IBM Langflow authenticated code generation flaw
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence90%
Public exploitation · VTP factUNKNOWN
Assessment
Langflow OSS 1.0.0 through 1.11.1 permits authenticated remote code execution through improper code generation controls. Metasploit coverage is public.
Why it matters
An authenticated user could execute arbitrary code on an affected Langflow service.
If you use affected Langflow, update and restrict access to trusted users until remediation is complete.
Evidence
2 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
Public tooling availability does not establish active exploitation.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Next watchpoint
Monitor unusual flow activity and server processes spawned by Langflow.
AI baseline history (2)
BASELINE ASSESSED
IBM Langflow authenticated code generation flawgpt-5.6-terra · low
BASELINE ASSESSED
Public exploit-oriented template reported for an unclassified CVEgpt-5.6-terra · low
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
A proof of concept is reported; functional reliability is not established.
02
EPSS is 0.02; this is predictive context, not exploitation evidence.
03
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
02
Material change ledger
What changed
EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
03
Claim provenance
Evidence and source independence
1publications detected
1underlying evidence chains
0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
Rapid7 Metasploit Framework published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.
Rapid7 Metasploit Framework recorded exploit-tooling coverage changes for 1 CVE in this pinned revision. 1 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.