HighVulnerability
CVE-2026-93677: IBM Langflow OSS sensitive information exposure to unauthorized actor
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-93677
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.5%
Summary
IBM Langflow OSS versions 1.0.0 through 1.12.2 contain a flaw that exposes sensitive information to an unauthorized actor. A remote attacker who has valid authentication can obtain that information.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- HighGHSA-6wjp-v33h-5cvq: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosureSimilar attack · GitHub Advisory Database
- HighCVE-2026-101998: Docker Sandboxes fail open when masking credentials in proxy responsesSimilar attack · NVD/CVE Database
- InfoAnytime-valid detection of LLM weight exfiltrationSimilar attack · Arxiv (cs.CR + cs.CL + cs.LG)
- InfoSystemic privacy risks of personal data exposure through conversational large language model agentsSimilar attack · OpenAlex (peer-reviewed AI security)
- InfoInverting Multi-Vector Visual Document IndicesSimilar attack · Arxiv (cs.CR + cs.CL + cs.LG)