CVE-2026-8447 IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a… — CVE Notify — TG.ME

🚨 CVE-2026-8447
IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface.

🎖@cveNotify
Ibm
Security Bulletin: Langflow is vulnerable to stored cross-site scripting and IP spoofing due to unsanitized Markdown rendering…
Langflow contains two vulnerabilities affecting client-side security and access control integrity. The MarkdownField component renders chat messages using the rehypeRaw plugin without a sanitization pass, causing attacker-controlled LLM response text containing…
September 4, 2026 17