IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components.
Advisories
No advisories yet.
Fixes
Solution
IBM recommends upgrading to Langflow OSS 1.11.0 or newer https://github.com/langflow-ai/langflow/releases
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7282648 |
|
History
Wed, 05 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components. | |
| Title | Langflow is affected by weaknesses in secret handling and sensitive configuration access | |
| First Time appeared |
Ibm
Ibm langflow Oss |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:ibm:langflow_oss:1.0.0:*:*:*:*:*:*:* cpe:2.3:a:ibm:langflow_oss:1.10.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm langflow Oss |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2026-08-05T17:42:08.504Z
Reserved: 2026-05-29T18:04:25.740Z
Link: CVE-2026-10128
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses