Description
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Published: 2026-07-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Langflow OSS versions 1.0.0 through 1.10.1 contain hard‑coded credentials that are used for inbound authentication, outbound communication, or encryption of internal data. This vulnerability is a CWE‑798 (Use of Hard‑Coded Credentials) weakness, which allows an attacker to gain unauthorized access to the application, potentially hijack sessions, and exfiltrate sensitive data. The exposed credentials also enable brute‑force or credential‑reuse attacks against integrated services, compromising downstream components. This vulnerability can result in full compromise of the affected system as well as associated privileged resources.

Affected Systems

IBM Langflow OSS v1.0.0 to v1.10.1 are affected. The latest fixed version is 1.10.2, to which users are strongly encouraged to upgrade.

Risk and Exploitability

The CVSS score is 9.8, indicating critical severity, while the EPSS score is less than 1 percent, suggesting a very low probability of mass exploitation at present. The vulnerability is listed as not in the CISA KEV catalog, but the lack of authentication on multiple API endpoints makes it highly exploitable when an attacker can reach the service. The likely attack vector involves sending crafted requests to the exposed endpoints over the network, assuming no network segmentation or firewall restrictions are in place. Given the high severity and the fact that credentials are hard‑coded, a successful exploit can lead to remote code execution, denial of service, and credential leakage on both the application and downstream systems.

Generated by OpenCVE AI on July 30, 2026 at 23:26 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.10.2


OpenCVE Recommended Actions

  • Upgrade IBM Langflow OSS to version 1.10.2 or later as per IBM guidance
  • Replace or remove hard‑coded credentials and rotate any exposed passwords or keys
  • Restrict network access to the Langflow API endpoints or enforce authentication to eliminate unauthenticated usage

Generated by OpenCVE AI on July 30, 2026 at 23:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Title Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-798
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.10.1:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Langflow Oss
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-23T03:56:14.257Z

Reserved: 2026-06-26T16:43:04.516Z

Link: CVE-2026-13446

cve-icon Vulnrichment

Updated: 2026-07-21T02:21:18.575Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:30:08Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials