Vulnerability PYSEC-2026-2565
Low Risk
LOW RISK
CVSS Score: 2.7
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
2 months ago
July 13, 2026 at 03:02 PM UTC
Langflow has an Information Leak through Incomplete API Key Redaction
0.0.31 - 1.8.3
0.0.31 - 1.8.3
Summary
Langflow has an Information Leak through Incomplete API Key Redaction
Details
A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flow Using API. This manipulation causes unprotected storage of credentials. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
2 months ago
Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
0.0.31 - 1.8.4 PYSEC-2026-2566
0.0.31 - 1.8.4 PYSEC-2026-2566
Medium Risk
2 months ago
Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
0.0.31 - 1.9.0 PYSEC-2026-2568
0.0.31 - 1.9.0 PYSEC-2026-2568
Medium Risk
2 months ago
Langflow vulnerable to injection
0.0.31 - 1.8.3 PYSEC-2026-2569
0.0.31 - 1.8.3 PYSEC-2026-2569
Unknown
2 months ago
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
0.0.31 - 1.5.0.post2 PYSEC-2026-2567
0.0.31 - 1.5.0.post2 PYSEC-2026-2567
Unknown
2 months ago
Langflow affected by Remote Code Execution via validate_code() exec()
0.0.31 - 1.7.3 PYSEC-2026-1525
0.0.31 - 1.7.3 PYSEC-2026-1525
Impacted packages
Timeline
Published
2 months ago
July 13, 2026 at 03:02 PM UTC
Last Modified
2 months ago
July 13, 2026 at 04:32 PM UTC