


Perceptive Security
SOC/SIEM Consultancy

IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, messag…
Published:
29 juni 2026 om 22:00:00
Alert date:
30 juni 2026 om 21:06:12
Source:
nvd.nist.gov
Enterprise Applications, Cloud & Virtualization, Zero-Day Vulnerabilities, Data Breach & Exfiltration, Web Technologies
CVE-2026-10134 affects IBM Langflow OSS versions 1.0.0 through 1.9.3, exposing a critical vulnerability allowing attackers to read all secrets accessible to the Langflow process. Attackers can read and modify flows, conversations, messages, file uploads, and saved components in the Langflow database. The vulnerability enables connection to internal services and abuse of cloud metadata endpoints. Lateral movement to other tenants on the same Langflow instance is possible. Persistence can be established by modifying public flow tool_code, causing attacker code to re-execute on every subsequent build triggered by any user via normal API calls. The vulnerability has a high criticality rating and impacts a wide range of Langflow deployments. IBM has published a support advisory for this issue.
Technical details
Mitigation steps:
Affected products:
IBM Langflow OSS 1.0.0
IBM Langflow OSS 1.9.3
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
