CVE-2026-12945: Langflow is affected by exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.
Other sources
Langflow OSS 1.10.0 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.2 - Operational
Address exposed credentials caused by multiple unauthenticated and insufficiently authorized API endpoints (rotate/revoke any credentials that may have been exposed).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12945?
The severity of CVE-2026-12945 is rated as high with a score of 7.1.
How do I fix CVE-2026-12945?
To fix CVE-2026-12945, ensure that proper access controls are implemented on API endpoints and upgrade to the latest version of IBM Langflow.
What are the risks associated with CVE-2026-12945?
CVE-2026-12945 poses a risk of exposed credentials and unauthorized access to sensitive build jobs.
Which versions of Langflow are affected by CVE-2026-12945?
CVE-2026-12945 affects IBM Langflow OSS versions 1.0.0 through 1.10.1.
Are unauthenticated API endpoints present in CVE-2026-12945?
Yes, CVE-2026-12945 includes multiple unauthenticated API endpoints that can be exploited.