IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to an indirect object reference through a user-controlled key.
IBM recommends addressing the vulnerability now by upgrading to IBM Langflow Desktop 1.9.0 or newer https://www.langflow.org/blog/langflow-1-9-desktop
If you are already using Langflow Desktop, upgrade in the application to version 1.9.0
To install Langflow Desktop for the first time, visit Langflow Desktop https://langflow.org/desktop . Download https://langflow.org/desktop