Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-13446: Langflow Exposes Hard-Coded Credentials
CVE-2026-13446
CVE-2026-13446
Summary
IBM Langflow's open-source version contains a serious security risk: its use of hard-coded passwords and keys. This means that anyone with access to the software can see these sensitive credentials, which can be used to access systems or data without authorization. Update to a newer version to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ibm | langflow oss | <= 1.10.1 |
| langflow | langflow |
>= 1.0.0, < 1.10.2 cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
Original title
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external ...
Original description
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
nvd CVSS3.1
9.8
Vulnerability type
CWE-798
Use of Hard-coded Credentials
Published: 17 Jul 2026 · Updated: 20 Jul 2026 · First seen: 17 Jul 2026