Description
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.
Published: 2026-09-04
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure
Action: Patch
AI Analysis

Impact

IBM Langflow OSS 1.0.0 through 1.11.2 is susceptible to information disclosure because sensitive credential fields are not fully scrubbed when flows are marked public. The flaw allows a remote attacker who can trigger a public flow to gather private data that belongs to other users through a cache collision in the MCP tool. This flaw is identified as CWE‑200, meaning that authentication or authorization controls are insufficient for protecting secrets.

Affected Systems

The vulnerability affects IBM Langflow OSS versions 1.0.0 up to and including 1.11.2. Users running any of those releases on Docker, Kubernetes, or as a Python package are potentially impacted. The specific product name, IBM Langflow OSS, includes the open‑source edition of the workflow automation tool.

Risk and Exploitability

The CVSS score of 7.5 indicates a moderate to high severity for information disclosure. Because no EPSS score is available, the likelihood of exploitation is not quantified, and the vulnerability is not yet listed in CISA’s KEV catalog. An attacker can exercise the vulnerable path by creating or accessing a public flow, thereby causing the tool to expose another user's credentials via the shared cache. The attack can be performed remotely without additional network access beyond the server hosting Langflow, implying a non‑local attack vector.

Generated by OpenCVE AI on September 4, 2026 at 20:58 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now by upgrading Langflow OSS to version 1.11.3 https://pypi.org/project/langflow/


OpenCVE Recommended Actions

  • Upgrade to Langflow OSS 1.11.3 or later
  • Restrict the use of public flows and review existing public flows to remove sensitive credential data before publishing
  • Limit permissions so that only authorized users can publish flows and access secrets

Generated by OpenCVE AI on September 4, 2026 at 20:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Langflow
Langflow langflow
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Langflow
Langflow langflow
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Fri, 04 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.
Title Langflow is vulnerable to information disclosure due to cross-user MCP tool cache collision and incomplete secret scrubbing on public flows
First Time appeared Ibm
Ibm langflow Oss
Weaknesses CWE-200
CPEs cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:langflow_oss:1.11.2:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm langflow Oss
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Apple Macos
Ibm Langflow Oss
Langflow Langflow
Linux Linux Kernel
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T16:47:49.078Z

Reserved: 2026-08-07T17:20:51.125Z

Link: CVE-2026-19300

cve-icon Vulnrichment

Updated: 2026-09-04T16:46:26.354Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T16:17:22.167

Modified: 2026-09-08T22:18:38.570

Link: CVE-2026-19300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T00:15:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor