CyberRota
← Ana sayfaya dön

CVE-2026-3346

MEDIUM · CVSS 6.4 EPSS %0.03

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-04-30T21:16:32.610 · Çekilme zamanı: 2026-05-30T18:00:37.702190+00:00

CyberRota Yorumu

Saldırganın giriş yapmış olması gerekebilir.

CVE
CVE-2026-3346
Severity
MEDIUM
CVSS
6.4
EPSS
%0.03
Java

Orijinal NVD Açıklaması

IBM Langflow Desktop 1.6.0 through 1.8.4 Lanflow is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.