Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-10134: IBM Langflow OSS Secrets Exposure and Data Manipulation

CVE-2026-10134
Summary

IBM Langflow OSS versions 1.0.0 through 1.9.3 have a security flaw that allows an attacker to access sensitive information and manipulate data within the system. This could lead to unauthorized access to internal services and data breaches. To protect against this, it's recommended to update to the latest version of IBM Langflow OSS as soon as possible.

Original title
IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component i...
Original description
IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants on the same Langflow instance, and Establish persistence by modifying the public flow's `tool_code` so normal `/api/v1/build/...` calls by any user re-execute attacker code at each build.
nvd CVSS3.1 10.0
Vulnerability type
CWE-94 Code Injection
Published: 30 Jun 2026 · Updated: 23 Jul 2026 · First seen: 30 Jun 2026