No advisories yet.
Solution
IBM recommends addressing the vulnerability now by upgrading to IBM Langflow Desktop 1.9.0 or newer https://www.langflow.org/blog/langflow-1-8-desktopIf you are already using Langflow Desktop, upgrade in the application to version 1.9.0To install Langflow Desktop for the first time, visit Download Langflow Desktop.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7271095 |
|
Thu, 30 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Title | Stored Cross-Site Scripting (XSS) in Langflow Markdown Rendering via rehypeRaw | |
| First Time appeared |
Ibm
Ibm langflow Desktop |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:ibm:langflow_desktop:1.6.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:langflow_desktop:1.8.4:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm langflow Desktop |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-04-30T21:06:10.276Z
Reserved: 2026-02-27T16:11:36.537Z
Link: CVE-2026-3346
No data.
Status : Received
Published: 2026-04-30T21:16:32.610
Modified: 2026-04-30T21:16:32.610
Link: CVE-2026-3346
No data.
OpenCVE Enrichment
Updated: 2026-04-30T23:30:03Z