Impact
IBM Langflow OSS 1.0.0 through 1.11.2 is susceptible to information disclosure because sensitive credential fields are not fully scrubbed when flows are marked public. The flaw allows a remote attacker who can trigger a public flow to gather private data that belongs to other users through a cache collision in the MCP tool. This flaw is identified as CWE‑200, meaning that authentication or authorization controls are insufficient for protecting secrets.
Affected Systems
The vulnerability affects IBM Langflow OSS versions 1.0.0 up to and including 1.11.2. Users running any of those releases on Docker, Kubernetes, or as a Python package are potentially impacted. The specific product name, IBM Langflow OSS, includes the open‑source edition of the workflow automation tool.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate to high severity for information disclosure. Because no EPSS score is available, the likelihood of exploitation is not quantified, and the vulnerability is not yet listed in CISA’s KEV catalog. An attacker can exercise the vulnerable path by creating or accessing a public flow, thereby causing the tool to expose another user's credentials via the shared cache. The attack can be performed remotely without additional network access beyond the server hosting Langflow, implying a non‑local attack vector.
OpenCVE Enrichment