CVSS 7.5 · HIGH
CVE-2026-4503
IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to an indirect object reference through a user-controlled key.
View on NVDAnalysis
IBM Langflow Desktop versions 1.0.0 through 1.8.4 are susceptible to an IDOR vulnerability that exposes user images to unauthenticated attackers. By manipulating specific keys in requests, anyone can view private assets from other users. AI developers using this platform for prototyping should update their installations to secure their project data.
Severity
Score: 7.5(HIGH)
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NAV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: NONE
A: NONE
Weakness (CWE):
CWE-639EPSS
Probability of exploitation (next 30 days): 0.0005 (0.1%)
Percentile: 16.1%
EPSS: 2026-05-06
Technical description
IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to an indirect object reference through a user-controlled key.
Published: 4/30/2026, 9:16:33 PM
Last modified: 5/1/2026, 3:27:15 PM