CVE-2026-3357 - IBM Langflow Desktop FAISS Vector Store Remote Code Execution via malicious Pickle file
CVE ID :CVE-2026-3357
Published : April 8, 2026, 12:19 a.m. | 49 minutes ago
Description :IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 8, 2026, 12:19 a.m. | 49 minutes ago
Description :IBM Langflow Desktop 1.6.0 through 1.8.2 Langflow could allow an authenticated user to execute arbitrary code on the system, caused by an insecure default setting which permits the deserialization of untrusted data in the FAISS component.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...