IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another users private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content in their workflow output despite having no authorization to read the victims flow. Additionally, the attacker can pollute the victims collection by inserting their own documents into the shared namespace.
Allowing a .NET application to run at potentially escalated levels of access to the underlying operating and file systems can be dangerous and result in various forms of attacks.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Langflow | Langflow | 1.0.0 (including) | 1.10.2 (excluding) |