CVE-2026-10128: Langflow is affected by weaknesses in secret handling and sensitive configuration access
IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components.
Other sources
Langfloww OSS allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10128?
CVE-2026-10128 has a medium severity rating of 6.5.
What risks are associated with CVE-2026-10128?
CVE-2026-10128 allows authenticated users to read arbitrary server environment variables, exposing sensitive secrets.
Who is affected by CVE-2026-10128?
CVE-2026-10128 affects users of IBM Langflow OSS versions 1.0.0 through 1.10.3.
How do I mitigate the risks of CVE-2026-10128?
To mitigate CVE-2026-10128, ensure that all users are authenticated securely and limit access to sensitive configurations.
Is there a patch available for CVE-2026-10128?
As of now, specific patch details for CVE-2026-10128 have not been publicly released.