
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3357 is an insecure deserialization vulnerability in IBM Langflow Desktop that allows an authenticated user to execute arbitrary code on the affected system. The flaw exists in versions 1.6.0 through 1.8.2 of IBM Langflow Desktop, caused by an insecure default setting that permits deserialization of untrusted data in the FAISS (Facebook AI Similarity Search) component. It was published on April 8, 2026, with a patch available for versions beyond 1.8.2. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, IBM Advisory).
The root cause is classified as CWE-502 (Deserialization of Untrusted Data): IBM Langflow Desktop's FAISS component is configured by default to deserialize data without adequate validation or integrity checks, enabling an attacker to supply a malicious serialized payload. The attack vector is network-based with low attack complexity and requires only low-level authenticated access — no user interaction is needed. An attacker with valid credentials can craft a malicious serialized object and submit it to the FAISS component, triggering arbitrary code execution upon deserialization. This vulnerability maps to CAPEC-586 (Object Injection) (GitHub Advisory).
Successful exploitation grants an authenticated attacker the ability to execute arbitrary code on the host system, resulting in high impact to confidentiality, integrity, and availability. An attacker could access sensitive data stored or processed by the Langflow Desktop application, modify system files or application data, and disrupt service availability. Given that Langflow Desktop is an AI workflow tool that may interact with sensitive data pipelines and models, exploitation could also facilitate lateral movement within connected environments (GitHub Advisory, IBM Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). No threat actor attribution has been reported. The EPSS score is approximately 0.072% (per Feedly data), indicating a currently low probability of exploitation within the next 30 days, though the GitHub Advisory Database notes an EPSS of 0.63% (71st percentile). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time.
pickle module or a similar serialization format used by FAISS integrations) that encodes an arbitrary OS command or reverse shell.cmd.exe, powershell.exe, bash, python, curl, wget); unexpected process execution under the Langflow service account..pkl files) in application directories.IBM has released a patch addressing this vulnerability; users should upgrade IBM Langflow Desktop to version 1.8.3 or later (IBM Advisory, GitHub Advisory). If immediate patching is not feasible, restrict network access to the Langflow Desktop instance and limit authentication credentials to trusted users only. Additionally, monitor systems for suspicious code execution activities and review access logs for unauthorized authentication attempts.
The vulnerability received coverage from security news aggregators and threat intelligence platforms shortly after disclosure, including The Hacker Wire, Red Packet Security, and CISA's weekly vulnerability bulletin for the week of April 6, 2026. Social media activity was noted on platforms including Bluesky and Twitter/X, primarily from automated CVE tracking accounts. No significant vendor statements beyond the IBM advisory or notable independent researcher commentary have been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."