- A security update has been released to address a vulnerability in an IBM product.
- the affected product is IBM Langflow Desktop, and versions 1.0.0 through 1.8.4 are affected.
- CVE-2026-4503 is an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability that occurs in the Langflow Desktop image download endpoint.
- CVE-2026-6543 is a Remote Code Execution (RCE) vulnerability that occurs in the Langflow Code Validation endpoint, which could allow a threat actor to remotely execute arbitrary code.
- a patch has been made available in the latest update, and updating to IBM Langflow Desktop version 1.9.0 or later will resolve the vulnerability.
- please follow the instructions on the reference site to update to the latest version of the Vulnerability Patch.