CVE-2026-6543

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
30/04/2026
Last modified:
11/05/2026

Description

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:langflow:langflow_desktop:*:*:*:*:*:*:*:* 1.0.0 (including) 1.8.4 (including)


References to Advisories, Solutions, and Tools