CVE-2024-48061: Code Injection
Published Nov 4, 2024
·Updated
langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox.
Affected Software
2 affected components
pip/langflow<=1.0.18
Langflow Langflow<=1.0.18
Event History
Nov 4, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
Affected Software
Nov 5, 2024
Advisory Published
via GitHub·12:31 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-48061?
CVE-2024-48061 is classified as a high-severity vulnerability due to its Remote Code Execution (RCE) risk.
2
How do I fix CVE-2024-48061?
To remediate CVE-2024-48061, upgrade langflow to version 1.0.19 or later, which addresses this vulnerability.
3
What components are affected by CVE-2024-48061?
CVE-2024-48061 affects langflow versions up to and including 1.0.18.
4
What kind of attack does CVE-2024-48061 enable?
CVE-2024-48061 enables Remote Code Execution (RCE) attacks due to unsandboxed code execution on the local machine.
5
Is there a workaround for CVE-2024-48061 if I cannot upgrade?
There are no recommended workarounds for CVE-2024-48061, so upgrading to a secure version is essential.