CVE-2026-10128
EUVD-2026-5354405.08.2026, 18:16
IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| langflow | langflow | 1.0.0 ≤ 𝑥 < 1.11.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration