CVE-2026-93677: Langflow OSS is affected by multiple vulnerabilities
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to exposure of sensitive information to an unauthorized actor.
Other sources
Langflow OSS could allow a remote authenticated attacker to obtain sensitive information due to exposure of sensitive information to an unauthorized actor.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Langflow OSSto a version that resolves this vulnerability.Fixed in 1.12.3
Event History
Frequently Asked Questions
Who is able to exploit this issue?
A remote attacker must be authenticated to exploit the reported information-exposure issue. The available data does not identify any required privilege level beyond authentication.
Which versions are affected?
IBM Langflow OSS versions 1.0.0 through 1.12.2 are identified as affected.
What is the potential impact?
An authenticated remote attacker could obtain sensitive information that is exposed to an unauthorized actor. The provided scoring indicates high confidentiality impact, with no stated integrity or availability impact.