
CVE-2026-3346: stored XSS in IBM Langflow 1.6.0-1.8.4. Authenticated attacker injects JS into Web UI fields, steals cookies/sessions. No patch, no exploit in wild. CVSS 6.4, but credential disclosure risk is real. Pin your versions.... #CVE #infosec #ibm https://www.valtersit.com/cve/2026/04/cve-2026-3346/
Post summary
The post discloses a stored XSS vulnerability (CVE-2026-3346) in IBM Langflow that allows authenticated users to inject JavaScript and steal session data, but notes no patch or active exploitation yet.


