Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-13446: Langflow Exposes Hard-Coded Credentials

CVE-2026-13446 CVE-2026-13446
Summary

IBM Langflow's open-source version contains a serious security risk: its use of hard-coded passwords and keys. This means that anyone with access to the software can see these sensitive credentials, which can be used to access systems or data without authorization. Update to a newer version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
ibm langflow oss <= 1.10.1
langflow langflow >= 1.0.0, < 1.10.2
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Original title
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external ...
Original description
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
nvd CVSS3.1 9.8
Vulnerability type
CWE-798 Use of Hard-coded Credentials
Published: 17 Jul 2026 · Updated: 20 Jul 2026 · First seen: 17 Jul 2026