Indirect Object Reference Vulnerability in IBM Langflow Desktop
CVE-2026-4503
7.5HIGH
What is CVE-2026-4503?
An indirect object reference vulnerability exists in IBM Langflow Desktop versions 1.0.0 through 1.8.4, allowing unauthenticated users to access images uploaded by other users. This security flaw arises from a user-controlled key that improperly exposes user content, presenting a significant risk to user data privacy and security. Organizations using this software should remain vigilant and apply necessary updates to mitigate potential risks.
Affected Version(s)
Langflow Desktop 1.0.0 <= 1.8.4