CVE-2026-13446: Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.10.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13446?
CVE-2026-13446 has a critical severity score of 9.8.
What vulnerabilities are associated with CVE-2026-13446?
CVE-2026-13446 is associated with remote code execution, denial of service, path traversal, and exposed credentials.
How do I fix CVE-2026-13446?
To fix CVE-2026-13446, update IBM Langflow OSS to the latest version that addresses these vulnerabilities.
How can I mitigate the risks of CVE-2026-13446?
Mitigate risks by revising API endpoint security, removing hard-coded credentials, and implementing proper authentication mechanisms.
What versions of Langflow are affected by CVE-2026-13446?
IBM Langflow OSS versions 1.0.0 through 1.10.1 are affected by CVE-2026-13446.