HighVulnerability
CVE-2026-101331: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-101331
- Published
- Record updated
Summary
IBM Langflow OSS versions 1.0.0 through 1.12.2 are affected by CVE-2026-101331. A remote authenticated attacker can obtain sensitive information because credentials are insufficiently protected.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- HighGHSA-6wjp-v33h-5cvq: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosureSimilar attack · GitHub Advisory Database
- HighCVE-2026-101998: Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read…Similar attack · NVD/CVE Database
- MediumEncrypted instructions trick Copilot CLI into spilling developer secretsSimilar attack · CSO Online
- HighCVE-2026-93677: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due…Similar attack · NVD/CVE Database
- HighCVE-2026-106119: LangChain is a framework for building LLM-powered applications. Prior to 1.3.1, MongoDBChatMessageHistory does not…Similar attack · NVD/CVE Database