CVE-2026-6543

high
Published 2026-04-30 · Modified 2026-05-11
CVSS v3
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
8.8

Description

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network.

Predictions

Exploit likelihood
92%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — https://www.ibm.com/support/pages/node/7271092

Application impact

VendorProductVersionsFixed
langflowlangflow_desktop{"startIncluding":"1.0.0","endIncluding":"1.8.4"}

References

CWEs

CWE-94

Verify integrity in audit chain (admin only). AS-IS.