{"data":{"id":"351edfde-dd86-4817-ab59-1ac73122e56f","title":"CVE-2026-13446: IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it","summary":"IBM Langflow OSS (open-source software) versions 1.0.0 through 1.10.1 contain hard-coded credentials (passwords or encryption keys built directly into the code), which the software uses for its own authentication, communication with external systems, and data encryption. This vulnerability allows attackers to potentially gain unauthorized access or compromise the security of systems using these versions.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13446","publishedAt":"2026-07-17T21:17:05.960Z","cveId":"CVE-2026-13446","cweIds":["CWE-798"],"cvssScore":"9.8","cvssSeverity":"critical","severity":"critical","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["IBM Langflow"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-07-17T21:17:05.960Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}