IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network.
References
| Link | Resource |
|---|---|
| https://www.ibm.com/support/pages/node/7271092 | Vendor Advisory |
Configurations
History
11 May 2026, 17:04
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.ibm.com/support/pages/node/7271092 - Vendor Advisory | |
| CPE | cpe:2.3:a:langflow:langflow_desktop:*:*:*:*:*:*:*:* | |
| First Time |
Langflow
Langflow langflow Desktop |
30 Apr 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-30 22:16
Updated : 2026-05-11 17:04
NVD link : CVE-2026-6543
Mitre link : CVE-2026-6543
CVE.ORG link : CVE-2026-6543
JSON object : View
Products Affected
langflow
- langflow_desktop
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
