CVE-2026-6597
published 2026-04-20CVE-2026-6597: A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file…
PriorityP417low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
EPSS
0.32%
23.7th percentile
A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flow Using API. This manipulation causes unprotected storage of credentials. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| langflow-ai | langflow | — | — |
| langflow-ai | langflow | — | — |
| langflow-ai | langflow | — | — |
| langflow-ai | langflow | — | — |
| langflow | langflow | 0 – 1.8.3 | — |
CVSS provenance
nvdv3.12.7LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
nvdv4.02.0LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.03.3LOWAV:N/AC:L/Au:M/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5jjf-wcvf-923w: A weakness has been identified in langflow-ai langflow up to 1
ghsa_unreviewed·2026-04-20
CVE-2026-6597 [MEDIUM] GHSA-5jjf-wcvf-923w: A weakness has been identified in langflow-ai langflow up to 1
A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flow Using API. This manipulation causes unprotected storage of credentials. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA
Langflow has an Information Leak through Incomplete API Key Redaction
ghsa·2026-04-20
CVE-2026-6597 [LOW] CWE-256 Langflow has an Information Leak through Incomplete API Key Redaction
Langflow has an Information Leak through Incomplete API Key Redaction
A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flow Using API. This manipulation causes unprotected storage of credentials. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
VulDB
langflow-ai langflow up to 1.8.3 Flow Using API core.py remove_api_keys/has_api_terms credentials storage
vuldb·2026-04-19
CVE-2026-6597 [LOW] langflow-ai langflow up to 1.8.3 Flow Using API core.py remove_api_keys/has_api_terms credentials storage
A vulnerability classified as problematic has been found in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flow Using API. This manipulation causes unprotected storage of credentials.
This vulnerability is handled as CVE-2026-6597. The attack can be initiated remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
No detection rules found.
No public exploits indexed.
2026-04-20
Published