PT-2026-36194 · Ibm · Langflow Desktop

Published

2026-04-30

·

Updated

2026-05-01

·

CVE-2026-3345

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Langflow Desktop versions prior to 1.8.5
Description An issue allows a remote attacker to perform directory traversal on the system. By sending a specially crafted URL request containing "dot dot" sequences (/../), an attacker can view arbitrary files on the system.
Recommendations Update to a version newer than 1.8.4.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-3345

Affected Products

Langflow Desktop