IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7268428 | Vendor Advisory |
Configurations
History
14 Apr 2026, 21:28
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* | |
| First Time |
Langflow langflow
Langflow |
|
| References | () https://www.ibm.com/support/pages/node/7268428 - Vendor Advisory |
08 Apr 2026, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-08 01:16
Updated : 2026-04-14 21:28
NVD link : CVE-2026-3357
Mitre link : CVE-2026-3357
CVE.ORG link : CVE-2026-3357
JSON object : View
Products Affected
langflow
- langflow
CWE
CWE-502
Deserialization of Untrusted Data
