CVE-2026-19300: Langflow is vulnerable to information disclosure due to cross-user MCP tool cache collision and incomplete secret scrubbing on public flows
IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.
Other sources
Langflow OSS could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Langflow OSSto a version that resolves this vulnerability.Fixed in 1.11.3 - Compensating control
Mitigate cross-user MCP tool cache collision and incomplete secret scrubbing on public flows by avoiding public flows where secrets/credentials could be exposed, until the system is upgraded to Langflow OSS 1.11.3.
Event History
Frequently Asked Questions
Which installations should be treated as affected?
IBM Langflow OSS versions 1.0.0 through 1.11.2 are identified as affected. The provided information does not limit exposure to a particular configuration or deployment type.
Does exploitation require an authenticated account or user interaction?
No. The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the expected security impact?
The issue can expose sensitive information, with high confidentiality impact. No integrity or availability impact is indicated by the supplied CVSS vector.