Known vulnerabilities in Langflow Desktop
Vendor:
IBM Corporation
Software:
Langflow Desktop
Software CPE:
cpe:2.3:a:ibm_corporation:langflow_desktop:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
4
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU128853 - Improper Control of Generation of Code ('Code Injection') CVE-2026-6543 |
CWE-94 | Medium | 1.9.0 | 01.05.2026 |
SB2026050127 |
||
| #VU128729 - Authorization Bypass Through User-Controlled Key CVE-2026-4503 |
CWE-639 | High | 1.9.0 | 01.05.2026 |
SB2026050105 |
||
| #VU117332 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-59343 |
CWE-22 | High | 1.8.4 | 17.10.2025 |
SB2025101702 SB2025101703 SB2025101704 and 22 more |
||
| #VU115167 - Allocation of Resources Without Limits or Throttling CVE-2025-58754 |
CWE-770 | Medium | 1.8.2 | 12.09.2025 |
SB2025091204 SB2025100104 SB2025100912 and 51 more |