CVE-2026-3357Disclosure(langflow / langflow)

LOWCVSS 8.8 · HIGH

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch langflow langflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 5 total mentions across 1 day

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-04-08: 5Patch / Workaround · 2026-04-08: 1Technical Details · 2026-04-08: 404-08
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Full discourse5 posts
  • cybersecuritypath@cybrsecpath
    Disclosure

    IBM Langflow Desktop RCE Flaw CVE-2026-3357 Allows Arbitrary Code Execution https://thecybrdef.com/ibm-langflow-desktop-rce-cve-2026-3357/

    Post summary

    The post announces an RCE vulnerability (CVE-2026-3357) in IBM Langflow Desktop that permits arbitrary code execution, but provides no proof of concept, exploitation details, or patch information.

    0000040
    3 followersView on X
  • CyberBriefDaily@CyberBriefDaily
    Patch

    🛡️ Cyber Byte #14 IBM Langflow Desktop RCE Flaw CVE-2026-3357 (CVSS 8.8) – Insecure deserialization in FAISS component allows authenticated remote code execution. Fix: Update Langflow Desktop to the latest version. https://www.thehackerwire.com/ibm-langflow-desktop-rce-via-insecure-deserialization/ #Langflow #RCE #AI #InsecureDeserialization #AISecurity #CyberBriefDaily

    Post summary

    IBM disclosed a CVE-2026-3357 insecure deserialization vulnerability in Langflow Desktop that allows authenticated RCE, and issued a patch to update to the latest version.

    0000056
    4 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3357 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Ibm Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3357 #CVE-2026-3357 #CVE #High #Ibm #CyberSecurity #InfoSec https://t.co/ABu8heUD4v

    Post summary

    A new CVE (CVE-2026-3357) with high severity is announced, affecting IBM; no PoC, exploit, patch, or technical details are supplied.

    0000043
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3357 IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which… https://www.cve.org/CVERecord?id=CVE-2026-3357

    Post summary

    The tweet announces a CVE for IBM Langflow Desktop that permits authenticated users to execute arbitrary code due to an insecure default setting.

    00000103
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3357: HIGH] IBM Langflow Desktop 1.6.0-1.8.2 vulnerability allows code execution by an authenticated user due to insecure settings permitting deserialization of untrusted data in FAISS component.#cve,CVE-2026-3357,#cybersecurity https://cvefind.com/CVE-2026-3357

    Post summary

    The tweet discloses that IBM Langflow Desktop vulnerability CVE-2026-3357 permits authenticated code execution through deserialization of untrusted data, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000057
    619 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more