Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6597

17
FAUCET Score

A vulnerability (CVE-2026-6597) has been identified in Langflow-AI Langflow versions up to 1.8.3, affecting the remove_api_keys and has_api_terms functions in the Flow API component. The flaw results in unprotected storage of credentials within the application. This network-accessible vulnerability can be exploited remotely by authenticated users with high-level privileges to access sensitive authentication data. The CVSS v3.1 base score of 2.7 (LOW) reflects limited confidentiality impact, though the vulnerability has been added to active threat tracking lists. Public exploit code is available, and despite early vendor notification, the vendor has not responded with patches or mitigation guidance, leaving affected deployments vulnerable to credential exposure attacks.

Impacted Technologies

VendorProductVersion(s)CPE
Langflow-AiLangflow
1.8.0, 1.8.1, 1.8.2, 1.8.3CNA affected

CVSS Data

CVSS version used by this source: 4.0

2.0LOW

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
24.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 38th percentile among its peer group of 709 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

pipGHSA-5jjf-wcvf-923wlow

Langflow has an Information Leak through Incomplete API Key Redaction

Apr 20, 2026

References

gist.github.com / chenhouser2025/b93261c6e651f14800a4f2e4365f357b
vuldb.com / submit/791920
vuldb.com / vuln/358232
vuldb.com / vuln/358232/cti