CVE-2026-10134Disclosure(langflow / langflow)

LOWCVSS 10.0 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch langflow langflow systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants on the same Langflow instance, and Establish persistence by modifying the public flow's `tool_code` so normal `/api/v1/build/...` calls by any user re-execute attacker code at each build.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-07-09)
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-06-30: 1Mentions · 2026-07-01: 1Mentions · 2026-07-04: 1Mentions · 2026-07-09: 2Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-04: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-04: 1Technical Details · 2026-07-09: 206-3007-0107-0407-09
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-06-301
Disclosure1
2026-07-011
Patch1
2026-07-041
Patch1
2026-07-092
Disclosure1General1
Full discourse5 posts
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Multiple Langflow OSS vulnerabilities, including the critical CVE-2026-10134 flaw, expose servers to code execution. Patch immediately. #Langflow #Vulnerabilities #CyberSecurity #CVE202610134 #InfoSec http://securityonline.info/langflow-oss-vulnerabilities/

    Post summary

    The text alerts to a critical CVE-2026-10134 in Langflow OSS that allows code execution and urges immediate patching.

    00152935
    12.9K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-10134 — CVSS 10/10 ██████████ IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/eSyrNTpqpf

    Post summary

    IBM Langflow OSS versions 1.0.0 through 1.9.3 are vulnerable (CVE‑2026‑10134) to secret leakage; a patch has been released to address the critical flaw.

    1000086
    63 followersView on X
  • Cyberdark Impact@kenebeii
    General

    🔐 セキュリティトレンド (12:43 JST) ① 開発環境への不正アクセスでランサムメッセージ残置-Dockerと自宅ルーターの二重の設定不備が原因 https://rocket-boys.co.jp/security-measures-lab/docker-localhost-binding-security-guide/ ② IBMが発見-未認証RCEからAPIキーの越境流用まで広範囲に影響(CVE-2026-10134 https://rocket-boys.co.jp/security-measures-lab/langflow-unauthenticated-rce-cve-2026-10134/ ③ 「Codex」と「Claude」と4700行のコードで大規模スパム攻撃を止めた体験記 - (page 2) https://japan.zdnet.com/article/35249933/2/ ④ IBMとRed Hat、「Project Lightwell」を始動--AI悪用の攻撃から防御 - ZDNET Japan https://japan.zdnet.com/article/35250368/ ⑤ イラン「攻撃受けたら2倍の反撃」米を牽制“ホルムズ海峡完全封鎖”も 国営メディア - テレ朝NEWS https://news.tv-asahi.co.jp/news_international/articles/000517865.html #セキュリティ #CyberSecurity

    Post summary

    The tweet lists several security topics, including CVE‑2026‑10134 described as an unauthenticated RCE affecting API keys, but provides only technical details without evidence of active exploitation, PoC, or patches.

    00000239
    1.3K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    Langflowに重大な脆弱性6件、IBMが発見-未認証RCEからAPIキーの越境流用まで広範囲に影響(CVE-2026-10134、CVE-2026-7803、CVE-2026-7871、CVE-2026-7873、CVE-2026-10140、CVE-2026-7663) https://rocket-boys.co.jp/security-measures-lab/langflow-unauthenticated-rce-cve-2026-10134/ #セキュリティ対策Lab #security #securitynews

    Post summary

    IBM discovered six critical vulnerabilities in Langflow, including unauthenticated RCE and API key hijacking, as reported in the linked article.

    00000158
    462 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - IBM Langflow OSS Code Injection with Full Compromise & Persistence (CVE-2026-10134) IBM Langflow OSS 1.0.0 through 1.9.3 contains a code injection flaw that gives an attacker sweeping control: read every secret available to the Langflow process; read and modify every flow, conversation, message, file upload, and saved component in the database; reach internal services; abuse cloud metadata endpoints; and laterally move to other tenants on the same instance. The attacker can also establish persistence by modifying the public flow's tool_code, so ordinary /api/v1/build/... calls by any user re-execute the attacker's code on every build. The flaw is remotely exploitable with no privileges and no user interaction - a maximum-severity CVSS 10.0. 👉Affected: IBM Langflow OSS 1.0.0–1.9.3; apply IBM's fix (see IBM advisory).

    Post summary

    The post announces a high-severity code injection vulnerability in IBM Langflow OSS (CVE-2026-10134), detailing its impact and urging users to apply the vendor patch.

    00000102
    232 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more