Description
IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components.
Published: 2026-08-05
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.10.3 contain a flaw that allows any authenticated user to use a built‑in component to read arbitrary server environment variables. The vulnerability bypasses security controls that are supposed to disable custom components, revealing confidential secrets that could include API keys or database credentials. It is classified as CWE‑200, representing information disclosure and directly threatens the confidentiality of the system.

Affected Systems

The affected product is IBM Langflow OSS. Versions 1.0.0, 1.10.3, and all releases in between are vulnerable. The vendor’s official advisory recommends upgrading to version 1.11.0 or newer to remediate the flaw.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, reflecting that the attacker must first be authenticated to the application. The EPSS score is not available, so the current likelihood of exploitation is unclear. The vulnerability is not listed in the CISA KEV catalog, and no remote exploitation vector is described in the advisory. The attack likely requires access to a valid user account and the ability to invoke the vulnerable component within the application interface.

Generated by OpenCVE AI on August 5, 2026 at 20:05 UTC.

Remediation

Vendor Solution

IBM recommends upgrading to Langflow OSS 1.11.0 or newer https://github.com/langflow-ai/langflow/releases


OpenCVE Recommended Actions

  • Apply the vendor’s patch by upgrading to Langflow OSS 1.11.0 or later.
  • If upgrade is not immediately possible, disable or remove the custom component that provides access to environment variables, ensuring any configuration that allows its use is turned off.
  • Enable application logging and monitor for unauthorized or anomalous usage of the vulnerable component, alerting administrators to potential exploitation.

Generated by OpenCVE AI on August 5, 2026 at 20:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components.
Title Langflow is affected by weaknesses in secret handling and sensitive configuration access
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-200
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.10.3:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Langflow Oss
Langflow Langflow
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-06T14:32:28.911Z

Reserved: 2026-05-29T18:04:25.740Z

Link: CVE-2026-10128

cve-icon Vulnrichment

Updated: 2026-08-06T14:32:21.899Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-05T18:16:51.123

Modified: 2026-08-06T19:00:35.777

Link: CVE-2026-10128

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T20:15:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor