VYPR
Unrated severityNVD Advisory· Published Aug 5, 2026

Langflow is affected by weaknesses in secret handling and sensitive configuration access

CVE-2026-10128

Description

IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.