Junglewise Threat Intelligence

CVE-2026-4503: IBM Langflow Desktop IDOR in image download endpoint

CVE-2026-4503 · Severity: high · CVSS 7.5 · Published 2026-04-30

Technologies: IBM Langflow Desktop. Vendors: IBM.

Executive brief

IBM Langflow Desktop, a tool used for building AI workflows, contains a security flaw that allows unauthorized individuals to view images belonging to other users. By exploiting this vulnerability, an attacker could access sensitive visual data or proprietary information stored within the application without needing to log in. This could lead to data exposure and a breach of privacy for users of the platform.

Technical details

IBM Langflow Desktop versions 1.0.0 through 1.8.4 are vulnerable to an Insecure Direct Object Reference (IDOR) in the image retrieval functionality. The endpoint 'GET /api/v1/files/images/{flow_id}/{file_name}' fails to enforce proper authentication and ownership validation. An unauthenticated remote attacker can exploit this by supplying a valid flow identifier and filename to retrieve image assets belonging to other users. This behavior is inconsistent with other file endpoints in the application which are properly protected. The vulnerability is addressed in version 1.9.0.

Affected products

  • IBM Langflow Desktop 1.0.0 - 1.8.4

Timeline

  • 2026-04-28: advisory: Initial publication of IBM security bulletin
  • 2026-04-30: disclosed: CVE-2026-4503 published

References

Related threats