CVE 8.8 HIGH

Authenticated Remote Code Execution Vulnerability in Langflow Code Validation Endpoint_CVE-2026-6543

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network.

AI Analysis

Authenticated Remote Code Execution Vulnerability in Langflow Code Validation Endpoint

Basic Information

ID CVE-2026-6543
Source ibm
Published Apr 30, 2026 at 21:11

Affected Product

Vendor IBM
Product Langflow Desktop
Version 1.0.0
Affected Versions IBM Langflow Desktop 1.0.0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor IBM
Product Langflow Desktop
Version 1.0.0-1.8.4

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.