Skip to content
CVSS 7.5 · HIGH

CVE-2026-4503

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to an indirect object reference through a user-controlled key.

View on NVD

Analysis

IBM Langflow Desktop versions 1.0.0 through 1.8.4 are susceptible to an IDOR vulnerability that exposes user images to unauthenticated attackers. By manipulating specific keys in requests, anyone can view private assets from other users. AI developers using this platform for prototyping should update their installations to secure their project data.

Severity

Score: 7.5(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: NONE
A: NONE
Weakness (CWE): CWE-639

EPSS

Probability of exploitation (next 30 days): 0.0005 (0.1%)
Percentile: 16.1%
EPSS: 2026-05-06

Technical description

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to an indirect object reference through a user-controlled key.

Published: 4/30/2026, 9:16:33 PM
Last modified: 5/1/2026, 3:27:15 PM

References

HomeEventsBlogResourcesTeam