Stored Cross-Site Scripting Vulnerability in IBM Langflow Desktop
CVE-2026-3346
6.4MEDIUM
What is CVE-2026-3346?
IBM Langflow Desktop versions 1.6.0 to 1.8.4 are susceptible to a stored cross-site scripting vulnerability. This flaw enables an authenticated user to inject arbitrary JavaScript code into the Web UI. As a result, the normal functionality of the application can be altered, potentially leading to the disclosure of sensitive information such as user credentials during a trusted session. It is crucial for users of these versions to apply the necessary patches to mitigate this risk.
Affected Version(s)
Langflow Desktop 1.6.0 <= 1.8.4