IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.
History

Wed, 08 Apr 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 01:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.
Title IBM Langflow Desktop FAISS Vector Store Remote Code Execution via malicious Pickle file
First Time appeared Ibm
Ibm langflow Desktop
Weaknesses CWE-502
CPEs cpe:2.3:a:ibm:langflow_desktop:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_desktop:1.8.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Desktop
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2026-04-08T00:19:11.414Z

Updated: 2026-04-08T15:41:55.112Z

Reserved: 2026-02-27T18:17:58.431Z

Link: CVE-2026-3357

cve-icon Vulnrichment

Updated: 2026-04-08T15:41:50.528Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-08T01:16:41.057

Modified: 2026-04-08T21:26:35.910

Link: CVE-2026-3357

cve-icon Redhat

No data.