IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7268428 |
|
History
Wed, 08 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component. | |
| Title | IBM Langflow Desktop FAISS Vector Store Remote Code Execution via malicious Pickle file | |
| First Time appeared |
Ibm
Ibm langflow Desktop |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:ibm:langflow_desktop:1.6.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:langflow_desktop:1.8.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm langflow Desktop |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published: 2026-04-08T00:19:11.414Z
Updated: 2026-04-08T15:41:55.112Z
Reserved: 2026-02-27T18:17:58.431Z
Link: CVE-2026-3357
Updated: 2026-04-08T15:41:50.528Z
Status : Awaiting Analysis
Published: 2026-04-08T01:16:41.057
Modified: 2026-04-08T21:26:35.910
Link: CVE-2026-3357
No data.