Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g2wf-gm3w-w9x3

Опубликовано: 08 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.

EPSS

Процентиль: 38%
0.00466
Низкий

8.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.8
nvd
4 месяца назад

IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.

CVSS3: 8.8
fstec
4 месяца назад

Уязвимость программного обеспечения для визуальной разработки ИИ-агентов IBM Langflow Desktop, связанная с недостатками механизма десериализации, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 38%
0.00466
Низкий

8.8 High

CVSS3

Дефекты

CWE-502