CVE-2026-3357
Last modified
CVE-2026-3357 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Langflow | Langflow | >= 1.6.0, < 1.8.3 |
References
- https://www.ibm.com/support/pages/node/7268428Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-3357?
How severe is CVE-2026-3357?
How do I fix CVE-2026-3357?
Are you affected by CVE-2026-3357?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
