IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7271092 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-04-30 22:16
Updated : 2026-06-17 11:00
NVD link : CVE-2026-6543
Mitre link : CVE-2026-6543
CVE.ORG link : CVE-2026-6543
JSON object : View
Products Affected
langflow
- langflow_desktop
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
