IBM Product Security Update Advisory

IBM Product Security Update Advisory
  • A security update has been released to address a vulnerability in an IBM product.
  • the affected product is IBM Langflow Desktop, and versions 1.0.0 through 1.8.4 are affected.
  • CVE-2026-4503 is an unauthenticated Insecure Direct Object Reference (IDOR) vulnerability that occurs in the Langflow Desktop image download endpoint.
  • CVE-2026-6543 is a Remote Code Execution (RCE) vulnerability that occurs in the Langflow Code Validation endpoint, which could allow a threat actor to remotely execute arbitrary code.
  • a patch has been made available in the latest update, and updating to IBM Langflow Desktop version 1.9.0 or later will resolve the vulnerability.
  • please follow the instructions on the reference site to update to the latest version of the Vulnerability Patch.