CVE-2026-10128: Langflow is affected by weaknesses in secret handling and sensitive configuration access
IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0