Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6543

Опубликовано: 30 апр. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:langflow:langflow_desktop:*:*:*:*:*:*:*:*
Версия от 1.0.0 (включая) до 1.8.4 (включая)

EPSS

Процентиль: 38%
0.0047
Низкий

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
github
3 месяца назад

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment variables (API keys, DB credentials), modifying files, or launching further attacks on the internal network.

EPSS

Процентиль: 38%
0.0047
Низкий

8.8 High

CVSS3

Дефекты

CWE-94