ZeroHour

CVE-2026-19300

moderate

Sensitive credential disclosure in IBM Langflow OSS 1.0.0 through 1.11.2

CVSS 3.1
7.5 high
EPSS
<1%p31
Published
()
Modified
AI analysis

IBM Langflow OSS versions 1.0.0 through 1.11.2 fail to fully scrub sensitive credential fields, a CWE-200 information-exposure flaw that can leak secrets handled by the application. A remote attacker who can reach an affected Langflow instance over the network (CVSS 3.1 AV:N/AC:L/PR:N/UI:N, no privileges or user interaction required) can retrieve these incompletely scrubbed credential fields in output. Successful exploitation yields confidentiality impact only (C:H, I:N/A:N), giving the attacker access to sensitive credential material such as stored secrets, which could then be abused against dependent services. All deployments running Langflow OSS 1.0.0 through 1.11.2 are affected, with risk concentrated on instances reachable by untrusted networks. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts current exploitation probability at 0.4% over 30 days (31st percentile).

What to do: Update Langflow OSS to the first release after 1.11.2 as directed by IBM's advisory, since the data does not specify a fixed version number. Until patched, restrict network access to Langflow instances (firewall them from untrusted networks) and audit and rotate any credentials stored in Langflow if you find evidence of unauthorized access. Because the flaw is confidentiality-only, prioritize identifying instances where leaked keys could grant access to third-party services.

Affected
IBM Langflow OSS1.0.0 through 1.11.2
Estimated exposure
moderate≈1,000–10,000 instances plausibly exposed (order-of-magnitude estimate; tens of thousands of total self-hosted installs, most on internal networks) — Langflow is a widely adopted open-source AI workflow builder, but it is typically self-hosted by individual developers and small teams in local, Docker, or internal-network deployments, so the internet-exposed share is likely small…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote attacker to obtain sensitive information due to incomplete scrubbing of sensitive credential fields.

Vendors
langflow
Products
langflow
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.