A vulnerability (CVE-2026-6597) has been identified in Langflow-AI Langflow versions up to 1.8.3, affecting the remove_api_keys and has_api_terms functions in the Flow API component. The flaw results in unprotected storage of credentials within the application. This network-accessible vulnerability can be exploited remotely by authenticated users with high-level privileges to access sensitive authentication data. The CVSS v3.1 base score of 2.7 (LOW) reflects limited confidentiality impact, though the vulnerability has been added to active threat tracking lists. Public exploit code is available, and despite early vendor notification, the vendor has not responded with patches or mitigation guidance, leaving affected deployments vulnerable to credential exposure attacks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Langflow-Ai | Langflow | 1.8.0, 1.8.1, 1.8.2, 1.8.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.