CVE-2026-8447: IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat int
Summary
IBM Langflow OSS (an open-source software tool) versions 1.0.0 through 1.11.2 have a stored cross-site scripting vulnerability (XSS, a type of security flaw where malicious code gets saved in a system and runs when users view it) in its Playground chat feature. This means attackers could inject harmful code through the chat that would execute for other users.
Vulnerability Details
6.1(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
network
low
none
required
September 4, 2026
Classification
Affected Vendors
Related Issues
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
CVE-2024-27444: langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-8447
First tracked: September 4, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 85%