Skip to content
Threat Feed
critical advisory updated

Langflow Insecure Credential Encryption and Key Derivation

Langflow versions 1.10.0 and earlier use a non-cryptographic PRNG to derive Fernet keys from short SECRET_KEYs, allowing unauthenticated attackers who obtain the secret key file to perform offline decryption of all stored user credentials.

CVE search metadata

CVE search record: CVE-2026-9205. Severity: high. CVSS: 7.4. EPSS: 0.42%. KEV: no. Product: Langflow (<= 1.10.0), langflow (>= 1.7.2, < 1.10.1), Langflow (>= 1.3.0, < 1.10.3), Langflow (>= 1.5.0, < 1.10.3), langflow (< 1.10.3), langflow-base (< 0.10.3), lfx (< 1.10.3), Langflow (>= 1.6.8, <= 1.9.0). Brief: Langflow Insecure Credential Encryption and Key Derivation. Brief link: https://feed.craftedsignal.io/briefs/2026-10-langflow-weak-fernet/

What's new

  • 1. added coverage for Langflow (>= 1.6.8, <= 1.9.0) Oct 7, 22:48 via ghsa
  • 2. added detection rule: Detect CVE-2026-105697 Exploitation - MCP Server Creation Oct 7, 22:46 via ghsa
  • 3. added detection rule: Detect CVE-2026-105741 Exploitation - MCP Install Attempt with Spoofed Header Oct 7, 16:58 via ghsa
  • 4. added coverage for Langflow (>= 1.3.0, < 1.10.3) Oct 6, 00:48 via ghsa
  • 5. added detection rule: Detect CVE-2026-51886 Exploitation - Malicious Decorators in Validate Code API Oct 6, 00:48 via ghsa

Langflow versions 1.10.0 and earlier contain a critical cryptographic vulnerability in the handling of Fernet encryption keys used for storing sensitive user credentials, such as LLM API keys and database passwords. The application's _ensure_valid_key function incorrectly utilizes Python's non-cryptographic random module (Mersenne Twister) seeded with the instance's SECRET_KEY when that key is shorter than 32 characters. Because this process is fully deterministic, an attacker who obtains the secret_key file can recreate the encryption key offline without brute force. Furthermore, even when the SECRET_KEY is 32 characters or longer, the application uses the raw key directly as the Fernet key. This flaw is particularly dangerous when paired with file-read vulnerabilities, such as the MCP path traversal, which allow unauthorized access to the secret_key file and the underlying SQLite database. Once these files are exfiltrated, an attacker can decrypt all stored Credential-type variables across the entire instance.

Attack Chain

  1. Attacker identifies a target Langflow instance (v1.10.0 or earlier).
  2. Attacker leverages an auxiliary vulnerability, such as MCP path traversal (GHSA-95rw-c7w3-xh7f), to bypass access controls.
  3. Attacker exfiltrates the configuration file located at /app/data/.cache/langflow/secret_key.
  4. Attacker exfiltrates the application database file langflow.db using the same file-read primitive.
  5. Attacker checks the length of the exfiltrated secret_key to determine if the PRNG branch or raw-key branch applies.
  6. Attacker executes an offline decryption script using the recovered secret_key and the extracted ciphertext from the variable table.
  7. Attacker successfully recovers all stored API keys, database passwords, and OAuth tokens for all users on the instance.

Impact

Successful exploitation allows for the complete compromise of all stored credentials on a Langflow instance. This includes sensitive third-party API keys (OpenAI, Anthropic), database connection strings, and webhook secrets. In multi-tenant environments, this vulnerability permits a single attacker with low-level privileges to exfiltrate every credential stored by every user on the platform. The decryption process is entirely offline, ensuring the attacker leaves no server-side log traces during the credential recovery phase.

Recommendation

  1. Upgrade Langflow to version 1.10.1 or later immediately to implement secure SHA-256 key derivation and mitigate the weak PRNG issue.
  2. Rotate all API keys, database passwords, and other credentials previously stored in any Langflow instance that was running an affected version.
  3. Inspect file access logs for unauthorized attempts to read the /app/data/.cache/langflow/ directory or the langflow.db file to identify potential prior exploitation.
  4. Ensure that the SECRET_KEY is set to a cryptographically secure random string of at least 32 characters to align with updated security requirements.

Immediate actions

Upgrade Langflow to version 1.10.1 or later.

IT Operations 24h

Perform a global rotation of all credentials stored within the Langflow application.

IT Operations 48h

Mitigations

Upgrade to v1.10.1 to address CVE-2026-9205.

immediate IT Operations

CVE-2026-9205

Detection coverage 3

Detect CVE-2026-51886 Exploitation - Malicious Decorators in Validate Code API

high

Detects potential exploitation attempts of CVE-2026-51886 by monitoring for malicious Python decorators in requests to the Langflow validation API

sigma tactics: execution techniques: T1059.003 sources: webserver

Detect CVE-2026-105741 Exploitation - MCP Install Attempt with Spoofed Header

high

Detects exploitation attempts against the MCP configuration endpoint where the request originates from an external IP but claims local origin via X-Forwarded-For.

sigma tactics: initial_access, persistence sources: webserver

Detect CVE-2026-105697 Exploitation - MCP Server Creation

high

Detects POST or PATCH requests to the MCP server configuration endpoint which may be used to inject arbitrary system commands.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →