cvedb.io
CVE-2026-3357
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2026-04-08T01:16:41.057 · Last modified 2026-06-17T10:43:28.007

Summary

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.

Affected products

langflow — langflow

Does this affect you?

Add your gear to cvedb and we'll alert you only when langflow ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.