CVE Feed

    Dashboard / CVE / CVE-2026-10134

    CVE-2026-10134

    IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants on the same Langflow instance, and Establish persistence by modifying the public flow's `tool_code` so normal `/api/v1/build/...` calls by any user re-execute attacker code at each build.

    Published:Jun 30, 2026
    Last Modified:Jul 1, 2026
    EPS:Jun 30, 2026
    EPSS Score:0.00314
    CVSS Score:10

    Affected Products

    Vendor
    Ibm
    Product
    Langflow Oss

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High