CVE-2026-3346: Stored Cross-Site Scripting (XSS) in Langflow Markdown Rendering via rehypeRaw
IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3346?
CVE-2026-3346 is considered a high severity vulnerability due to its potential for stored cross-site scripting exploitation.
How do I fix CVE-2026-3346?
To fix CVE-2026-3346, upgrade IBM Langflow Desktop to a version later than 1.8.4.
Who is affected by CVE-2026-3346?
CVE-2026-3346 affects users of IBM Langflow Desktop versions 1.6.0 through 1.8.4.
What type of vulnerability is CVE-2026-3346?
CVE-2026-3346 is a stored cross-site scripting (XSS) vulnerability.
How can CVE-2026-3346 be exploited?
CVE-2026-3346 can be exploited by authenticated users embedding arbitrary JavaScript code in the Web UI.