Junglewise Threat Intelligence

CVE-2026-3340: IBM Langflow Desktop SSRF in URL component

CVE-2026-3340 · Severity: medium · CVSS 6.5 · Published 2026-04-30

Technologies: IBM Langflow Desktop. Vendors: IBM.

Executive brief

IBM Langflow Desktop, a tool used for building AI and machine learning workflows, contains a security flaw that allows users to make the server send unauthorized requests. An attacker could use this to probe internal corporate networks, access private data from local services, or interact with restricted cloud management interfaces. This could lead to the exposure of sensitive internal information or provide a foothold for further attacks on the organization's infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the URL data source component of IBM Langflow Desktop versions 1.0.0 through 1.8.4. The root cause is insufficient validation of user-supplied URLs before they are processed by the backend HTTP request handler. An authenticated attacker can exploit this to force the application to perform requests to internal or restricted network resources, including localhost services, private IP ranges, and cloud metadata endpoints. This can be used for network enumeration or to retrieve sensitive data from internal systems by relaying responses back through the Langflow execution flow. The vulnerability is addressed in version 1.9.0.

Affected products

  • IBM Langflow Desktop 1.0.0 - 1.8.4

Timeline

  • 2026-04-28: disclosed: Initial publication by IBM
  • 2026-04-30: advisory: NVD publication date
  • 2026-04-28: patched: Version 1.9.0 released to address the issue

References

Related threats