Sensitive Information Disclosure in IBM Langflow OSS
CVE-2026-10128
6.5MEDIUM
What is CVE-2026-10128?
IBM Langflow OSS versions 1.0.0 to 1.10.3 contain a vulnerability that allows authenticated users to exploit a built-in component, granting unauthorized access to sensitive server environment variables. This exposure can reveal critical secrets, circumventing existing security measures designed to restrict access to custom components. Users should review their Langflow configurations and apply recommended security patches to mitigate this risk.
Affected Version(s)
Langflow OSS 1.0.0 <= 1.10.3