Skip to content
CVSS 8.8 · HIGH

CVE-2026-6543

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network.

View on NVD

Analysis

Langflow is a popular orchestration tool for LLM development and agent building. An RCE in this stack is highly relevant to developers using AI workflows, as it can lead to the compromise of sensitive environment variables like OpenAI or Anthropic API keys.

Severity

Score: 8.8(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-94

EPSS

Probability of exploitation (next 30 days): 0.0004 (0.0%)
Percentile: 12.5%
EPSS: 2026-05-06

Technical description

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network.

Published: 4/30/2026, 10:16:26 PM
Last modified: 5/1/2026, 3:27:15 PM

References

HomeEventsBlogResourcesTeam