CVE-2026-101331: Langflow OSS is affected by multiple vulnerabilities
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to insufficiently protected credentials.
Other sources
Langflow OSS could allow a remote authenticated attacker to obtain sensitive information due to insufficiently protected credentials.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.12.3
Event History
Frequently Asked Questions
Which installations are in the affected version range?
IBM Langflow OSS versions 1.0.0 through 1.12.2 are identified as affected.
Does an attacker need access to an account or user interaction to exploit this issue?
The vulnerability is remotely exploitable by an authenticated attacker, so low-level privileges are required. No user interaction is required.
What is the primary security impact?
The issue can expose sensitive information because credentials are insufficiently protected. The supplied severity vector indicates high confidentiality impact, with no indicated integrity or availability impact.