PT-2026-33706 · Langflow Ai · Langflow

Eric-F

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6600

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions langflow-ai langflow versions prior to 1.8.4
Description A flaw in the Frontend React Component Rendering, specifically within the file 'src/frontend/src/modals/IOModal/components/chatView/chatMessage/components/edit-message.tsx', allows for remote cross site scripting. Cross site scripting is a security gap where malicious scripts are injected into trusted websites.
Recommendations Update to a version newer than 1.8.3.

Exploit

Fix

Code Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-6600

Affected Products

Langflow