SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-8447

MEDIUM · CVSS 6.1 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

IBM Langflow OSS versions 1.0.0 to 1.11.2 are susceptible to a stored cross-site scripting vulnerability within the Playground chat interface, allowing attackers to inject malicious scripts that can be executed in the context of users' browsers. This could lead to unauthorized actions or data exposure for users interacting with the affected interface. Organizations using these versions should prioritize remediation to protect their users from potential exploitation.

CVE
CVE-2026-8447
Severity
MEDIUM
CVSS
6.1
EPSS
0.21%

Original NVD Description

IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface.

Related CVEs

Other vulnerabilities affecting the same vendor(s)