Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-13446: Langflow Exposes Hard-Coded Credentials

CVE-2026-13446 · published 2 months ago
Summary

IBM Langflow's open-source version contains a serious security risk: its use of hard-coded passwords and keys. This means that anyone with access to the software can see these sensitive credentials, which can be used to access systems or data without authorization. Update to a newer version to fix this issue.

What to do
  • Update langflow langflow to version 1.10.2 or later.
Affected software
VendorProductAffected versions
ibm langflow oss <= 1.10.1
langflow langflow >= 1.0.0, < 1.10.2
cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*
Original advisory text
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external ...
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-798Use of Hard-coded Credentials
Timeline
Published17 Jul 2026
Updated25 Sep 2026
First seen17 Jul 2026
Sources
CVE-2026-13446 · MITRE
Track software like this
Free during beta