CVE-2026-4503: Langflow Desktop
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to an indirect object reference through a user-controlled key.
Affected products
- Langflow Langflow Desktop: from 1.0.0, up to and including 1.8.4
Published 2026-04-30. Last modified 2026-06-17.