What is CVE-2026-10128?
In IBM Langflow OSS versions 1.0.0 through 1.10.3, an authenticated user can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components.
Azərbaycanca: IBM Langflow OSS-in 1.0.0-dən 1.10.3-ə qədər versiyalarında autentifikasiya olunmuş istifadəçi, sıradan çıxarılmış təhlükəsizlik nəzarətlərinə baxmayaraq, daxili Langflow komponentini istismar edərək server mühit dəyişənlərini oxuya bilir. Bu, həssas sirrlərin ifşasına səbəb olur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: IBM
FAQ2
Which versions of IBM Langflow OSS are affected by CVE-2026-10128?
This vulnerability affects IBM Langflow OSS versions 1.0.0 through 1.10.3.
What can an authenticated user achieve by exploiting CVE-2026-10128?
An authenticated user can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.