Vulnerabilities
Report: Complete Guide to CVE-2026-3346 - Stored Cross-Site Scripting (XSS) in Langflow Markdown Rendering via rehypeRaw
CVE ID :CVE-2026-3346 Published : April 30, 2026, 9:06 p.m. | 14 minutes ago Description :IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. Severity: 6.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Affected Product:
IBM Langflow