CVE-2026-3340
MEDIUMServer-Side Request Forgery (SSRF) in Langflow URL Component
Title source: cnaDescription
IBM Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Scores
CVSS v3
6.5
EPSS
0.0002
EPSS Percentile
6.6%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (1)
IBM/Langflow Desktop
1.0.0 - 1.8.4
Published
Apr 30, 2026
Tracked Since
May 01, 2026