CVE-2026-3346Disclosure(langflow / langflow_desktop)

LOWCVSS 6.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow_desktop

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-30); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
langflow_desktop

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-30: 2Mentions · 2026-05-03: 1Technical Details · 2026-04-30: 2Technical Details · 2026-05-03: 104-3005-03
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-302
Disclosure2
2026-05-031
Disclosure1
Full discourse3 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-3346: stored XSS in IBM Langflow 1.6.0-1.8.4. Authenticated attacker injects JS into Web UI fields, steals cookies/sessions. No patch, no exploit in wild. CVSS 6.4, but credential disclosure risk is real. Pin your versions.... #CVE #infosec #ibm https://www.valtersit.com/cve/2026/04/cve-2026-3346/

    Post summary

    The post discloses a stored XSS vulnerability (CVE-2026-3346) in IBM Langflow that allows authenticated users to inject JavaScript and steal session data, but notes no patch or active exploitation yet.

    00010111
    889 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3346 IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaSc… https://www.cve.org/CVERecord?id=CVE-2026-3346

    Post summary

    The tweet announces CVE-2026-3346, a stored XSS issue in IBM Langflow Desktop that permits authenticated users to inject arbitrary JavaScript.

    00010121
    57.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3346 IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaSc… https://www.cve.org/CVERecord?id=CVE-2026-3346 ----- Traducción: CVE-2026-3346 IBM… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-3346, a stored cross‑site scripting flaw in IBM Langflow Desktop (1.6.0‑1.8.4) that permits an authenticated user to embed arbitrary JavaScript.

    0000016
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow_desktop---

Explore more