CVE-2026-3357
8.8IBM · Langflow Desktop
IBM Langflow Desktop versions 1.6.0 through 1.8.2 are vulnerable to arbitrary code execution via insecure deserialization of untrusted data in the FAISS component.
Executive summary
A critical vulnerability in IBM Langflow Desktop 1.6.0 through 1.8.2 allows authenticated attackers to execute arbitrary code on the host system.
Vulnerability
This flaw involves the deserialization of untrusted data within the FAISS component, allowing an authenticated user to achieve remote code execution. The vulnerability stems from insecure default settings that fail to properly sanitize input before processing.
Business impact
Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary code with the privileges of the Langflow application. This could lead to full system compromise, data exfiltration, or lateral movement within the network. With a CVSS score of 8.8, this vulnerability represents a high risk to organizational integrity and security.
Remediation
Immediate Action: Upgrade to IBM Langflow Desktop version 1.8.3 or newer immediately to apply the patch for the deserialization flaw.
Proactive Monitoring: Monitor system logs for unusual process execution or unauthorized attempts to access or modify local data files associated with the FAISS component.
Compensating Controls: Ensure that the application is running within a restricted environment or container with minimal filesystem permissions to limit the potential impact of an exploit.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for remote code execution, organizations should prioritize upgrading their Langflow Desktop instances to version 1.8.3. Failure to update leaves the system exposed to attackers who have already gained authenticated access to the environment.
More IBM CVEs
Sources
Originally found and disclosed by This vulnerability was reported to IBM by Weblover., per the CVE Program record.