Skip to content
LangflowGHSA-5jjf-wcvf-923w

Langflow has an Information Leak through Incomplete API Key Redaction

Low2.7CVE-2026-6597 · Published Apr 20, 2026 · updated Jul 13, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
langflow
PyPI
<= 1.8.3No fix yet
Details and references

A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flow Using API. This manipulation causes unprotected storage of credentials. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-256
Also known as
CVE-2026-6597, PYSEC-2026-2565

More Langflow advisories

All Langflow
DateAdvisory
Apr 20Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
CVE-2026-6598Low4.3fixed in 1.9.1
Apr 20Langflow vulnerable to injection
CVE-2026-6599Low6.3no fix yet
May 5Langflow Knowledge Bases API is Vulnerable to Path Traversal
CVE-2026-42048Critical9.6fixed in 1.9.0
Mar 27Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
CVE-2026-34046Highfixed in 1.5.1
Mar 26Langflow has Authenticated Code Execution in Agentic Assistant Validation
CVE-2026-33873Criticalfixed in 1.9.0
Mar 20langflow: /profile_pictures/{folder_name}/{file_name} endpoint file reading
CVE-2026-33497Highfixed in 1.7.1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.