IBM disclosed multiple severe vulnerabilities in Langflow OSS affecting versions 1.0.0 through 1.10.1, including remote code execution, denial of service, path traversal, unauthorized file and vector store access, build job information disclosure, and exposed credentials through unauthenticated or insufficiently authorized API endpoints. The most prominent issue, CVE-2026-13446, is a hard-coded credentials flaw classified as CWE-798 and scored CVSS 9.8, creating a network-exploitable path to compromise confidentiality, integrity, and availability.
According to IBM's bulletin, the vulnerable endpoints could let attackers execute code, read arbitrary files, access secrets, modify other users' data, and cancel active builds without proper authorization. IBM advised users to upgrade Langflow OSS to 1.10.2 to remediate the issues, as the affected releases expose both application internals and connected external components to critical compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2026-13446 notes that the update was received by psirt@us.ibm.com. The issue covers a hard-coded credentials vulnerability in IBM Langflow OSS with severe potential impact.
IBM published a security bulletin describing multiple severe vulnerabilities in Langflow OSS, including CVE-2026-13446, affecting versions 1.0.0 through 1.10.1. The bulletin recommends upgrading to version 1.10.2 and details risks including remote code execution, denial of service, path traversal, exposed credentials, and unauthorized access to files, secrets, and build data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceibm.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.