CVE-2026-19300

7.5

IBM · Langflow OSS

IBM Langflow OSS versions 1.0.0 through 1.11.2 contain a vulnerability that allows remote attackers to access sensitive information due to improper credential scrubbing.

Executive summary

An unauthenticated remote attacker can exploit a sensitive information exposure vulnerability in IBM Langflow OSS to potentially compromise credentials.

Vulnerability

The application fails to properly scrub sensitive credential fields, leading to an exposure of sensitive information to unauthorized actors (CWE-200). This flaw is exploitable by an unauthenticated remote attacker with network access to the application.

Business impact

The exposure of sensitive credentials poses a significant risk to organizational security, as it could allow unauthorized access to backend systems, integrated services, or sensitive data stores. With a CVSS score of 7.5, this vulnerability is classified as High, reflecting the potential for severe impact on confidentiality even without user interaction or specialized privileges.

Remediation

Immediate Action: Upgrade IBM Langflow OSS to version 1.11.3 or later as specified in the official vendor security advisory.

Proactive Monitoring: Review application access logs for unusual patterns or attempts to access configuration or credential-related endpoints.

Compensating Controls: Implement network-level access controls or a Web Application Firewall (WAF) to restrict traffic to the Langflow instance to trusted IP addresses only until the patch is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the ease of exploitation and the critical nature of potential credential exposure, organizations must prioritize the update to version 1.11.3. Failure to patch this vulnerability could result in unauthorized administrative access or lateral movement within the environment.

More IBM CVEs all →

Sources