Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/ibm/langflow-oss

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

IBM Langflow OSS versions 1.0.0 through 1.12.2 contain a code injection vulnerability (CWE-94) that allows a remote authenticated attacker to execute arbitrary operating system commands due to improper neutralization of special elements in OS command generation. This vulnerability has a high severity score of 8.1 and affects confidentiality and integrity without impacting availability.

Join the discussion

IBM Langflow OSS versions 1.0.0 through 1.10.2 contain a server-side request forgery (SSRF) vulnerability. This flaw allows unauthenticated attackers to send unauthorized requests from the affected system. Exploitation could lead to network enumeration or assist in other attacks. The vulnerability has a medium severity rating with a CVSS score of 6.5. No patch or remediation information is currently provided.

Join the discussion

IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a vulnerability in the MCP Tools component where improper cache key isolation allows an authenticated attacker to access another user's MCP server context. This issue could lead to limited confidentiality and integrity impacts but does not affect availability.

Join the discussion

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

Join the discussion

IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical vulnerability that allows remote attackers to inject arbitrary code due to improper control of user input code. This vulnerability is identified as CWE-94, indicating code injection issues. The flaw can lead to complete compromise of confidentiality, integrity, and availability of the affected system.

Join the discussion

IBM Langflow OSS versions 1.0.0 through 1.10.1 contain an authorization bypass vulnerability that allows authenticated users to access and manipulate other users' build jobs. This occurs due to improper access control on log retrieval and unauthenticated build endpoints. The vulnerability is identified as CWE-639 and has a CVSS v3.1 score of 7.1, indicating high severity.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:npm/ibm/langflow-oss
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses