Junglewise Threat Intelligence

CVE-2026-8447: IBM Langflow OSS stored cross-site scripting in Playground chat

CVE-2026-8447 · Severity: medium · CVSS 6.1 · Published 2026-09-04

Technologies: IBM Langflow OSS, Apple macOS, Microsoft Windows, Langflow, Linux Kernel. Vendors: IBM, Apple, Microsoft, Langflow, Linux.

Executive brief

IBM Langflow OSS is a platform for building and deploying AI-powered workflows. A stored cross-site scripting vulnerability in the Playground chat interface allows attackers to inject malicious scripts into chat messages through LLM responses. When other users view the affected conversation, their browser executes the injected script, potentially stealing session tokens and enabling account takeover or remote code execution if the victim is a superuser.

Technical details

The vulnerability exists in the MarkdownField component, which renders chat messages using the rehypeRaw plugin without proper HTML sanitization (CWE-79). Attacker-controlled content from LLM responses is inserted directly into the browser DOM as raw HTML. The attack requires no authentication to craft a malicious response through a Langflow flow, but relies on user interaction (viewing the chat) to trigger execution. An attacker can deliver a stored XSS payload that steals session tokens or, when the victim is an administrator, chain the XSS to achieve remote code execution. IBM recommends upgrading to Langflow OSS version 1.11.3 or later.

Affected products

  • IBM Langflow OSS 1.0.0 through 1.11.2

Timeline

  • 2026-09-04: disclosed
  • 2026-09-04: patched: Fixed in version 1.11.3

References

Related threats