Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qgh-3gr3-38fg

Опубликовано: 01 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network.

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network.

EPSS

Процентиль: 38%
0.0047
Низкий

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network.

EPSS

Процентиль: 38%
0.0047
Низкий

8.8 High

CVSS3

Дефекты

CWE-94