Langflow Insecure Credential Encryption and Key Derivation
Langflow versions 1.10.0 and earlier use a non-cryptographic PRNG to derive Fernet keys from short SECRET_KEYs, allowing unauthenticated attackers who obtain the secret key file to perform offline decryption of all stored user credentials.
CVE search metadata
CVE search record: CVE-2026-9205. Severity: high. CVSS: 7.4. EPSS: 0.42%. KEV: no. Product: Langflow (<= 1.10.0), langflow (>= 1.7.2, < 1.10.1), Langflow (>= 1.3.0, < 1.10.3), Langflow (>= 1.5.0, < 1.10.3), langflow (< 1.10.3), langflow-base (< 0.10.3), lfx (< 1.10.3), Langflow (>= 1.6.8, <= 1.9.0). Brief: Langflow Insecure Credential Encryption and Key Derivation. Brief link: https://feed.craftedsignal.io/briefs/2026-10-langflow-weak-fernet/
What's new
- 1. added coverage for Langflow (>= 1.6.8, <= 1.9.0) Oct 7, 22:48 via ghsa
- 2. added detection rule: Detect CVE-2026-105697 Exploitation - MCP Server Creation Oct 7, 22:46 via ghsa
- 3. added detection rule: Detect CVE-2026-105741 Exploitation - MCP Install Attempt with Spoofed Header Oct 7, 16:58 via ghsa
- 4. added coverage for Langflow (>= 1.3.0, < 1.10.3) Oct 6, 00:48 via ghsa
- 5. added detection rule: Detect CVE-2026-51886 Exploitation - Malicious Decorators in Validate Code API Oct 6, 00:48 via ghsa
Langflow versions 1.10.0 and earlier contain a critical cryptographic vulnerability in the handling of Fernet encryption keys used for storing sensitive user credentials, such as LLM API keys and database passwords. The application's _ensure_valid_key function incorrectly utilizes Python's non-cryptographic random module (Mersenne Twister) seeded with the instance's SECRET_KEY when that key is shorter than 32 characters. Because this process is fully deterministic, an attacker who obtains the secret_key file can recreate the encryption key offline without brute force. Furthermore, even when the SECRET_KEY is 32 characters or longer, the application uses the raw key directly as the Fernet key. This flaw is particularly dangerous when paired with file-read vulnerabilities, such as the MCP path traversal, which allow unauthorized access to the secret_key file and the underlying SQLite database. Once these files are exfiltrated, an attacker can decrypt all stored Credential-type variables across the entire instance.
Attack Chain
- Attacker identifies a target Langflow instance (v1.10.0 or earlier).
- Attacker leverages an auxiliary vulnerability, such as MCP path traversal (GHSA-95rw-c7w3-xh7f), to bypass access controls.
- Attacker exfiltrates the configuration file located at
/app/data/.cache/langflow/secret_key. - Attacker exfiltrates the application database file
langflow.dbusing the same file-read primitive. - Attacker checks the length of the exfiltrated
secret_keyto determine if the PRNG branch or raw-key branch applies. - Attacker executes an offline decryption script using the recovered
secret_keyand the extracted ciphertext from thevariabletable. - Attacker successfully recovers all stored API keys, database passwords, and OAuth tokens for all users on the instance.
Impact
Successful exploitation allows for the complete compromise of all stored credentials on a Langflow instance. This includes sensitive third-party API keys (OpenAI, Anthropic), database connection strings, and webhook secrets. In multi-tenant environments, this vulnerability permits a single attacker with low-level privileges to exfiltrate every credential stored by every user on the platform. The decryption process is entirely offline, ensuring the attacker leaves no server-side log traces during the credential recovery phase.
Recommendation
- Upgrade Langflow to version 1.10.1 or later immediately to implement secure SHA-256 key derivation and mitigate the weak PRNG issue.
- Rotate all API keys, database passwords, and other credentials previously stored in any Langflow instance that was running an affected version.
- Inspect file access logs for unauthorized attempts to read the
/app/data/.cache/langflow/directory or thelangflow.dbfile to identify potential prior exploitation. - Ensure that the
SECRET_KEYis set to a cryptographically secure random string of at least 32 characters to align with updated security requirements.
Immediate actions
Upgrade Langflow to version 1.10.1 or later.
Perform a global rotation of all credentials stored within the Langflow application.
Mitigations
Upgrade to v1.10.1 to address CVE-2026-9205.
CVE-2026-9205
Detection coverage 3
Detect CVE-2026-51886 Exploitation - Malicious Decorators in Validate Code API
highDetects potential exploitation attempts of CVE-2026-51886 by monitoring for malicious Python decorators in requests to the Langflow validation API
Detect CVE-2026-105741 Exploitation - MCP Install Attempt with Spoofed Header
highDetects exploitation attempts against the MCP configuration endpoint where the request originates from an external IP but claims local origin via X-Forwarded-For.
Detect CVE-2026-105697 Exploitation - MCP Server Creation
highDetects POST or PATCH requests to the MCP server configuration endpoint which may be used to inject arbitrary system commands.
Detection queries are available on the platform. Get full rules →