Executive brief
IBM Langflow OSS is an open-source platform for building AI-powered applications using visual workflows. The vulnerability allows authenticated users to craft malicious requests that cause the server to make unauthorized outbound HTTP calls to internal networks, cloud metadata services, or other restricted endpoints, potentially exposing sensitive infrastructure information or enabling lateral movement attacks.
Technical details
The vulnerability exists in the unified model instantiation path where provider SDK clients (ChatOllama, ChatOpenAI) are constructed using tenant-controlled base URLs. The root cause is that the connector SSRF validation guard is not invoked when creating these clients, allowing authenticated attackers to bypass server-side request forgery protections. An authenticated user can specify arbitrary URLs (including loopback addresses, internal IP ranges, or cloud metadata endpoints) that the server will connect to on their behalf. This enables network reconnaissance, metadata service exploitation, or attacks against internal services. The vulnerability affects Langflow OSS versions 1.0.0 through 1.11.1; a patch is available in version 1.11.2.
Affected products
- IBM Langflow OSS 1.0.0 through 1.11.1
Timeline
- 2026-08-21: disclosed
- 2026-08-21: patched: Version 1.11.2 available