CVE-2026-6597Low· 2.7▾ SunlitLangflow has an Information Leak through Incomplete API Key Redaction
▾ Sunlit zone — Low / medium · no exploitation signal
impact 14.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flow Using API. This manipulation causes unprotected storage of credentials. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
langflow <= 1.8.3Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-6599Medium· 6.3Langflow vulnerable to injection
CVE-2026-6598Medium· 4.3Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
CVE-2026-34046HighLangflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
CVE-2026-0770HighLangflow affected by Remote Code Execution via validate_code() exec()
CVE-2024-48061Critical· 9.8Langflow vulnerable to remote code execution
CVE-2025-68477High· 7.7Langflow vulnerable to Server-Side Request Forgery