<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Langflow (&gt;= 1.7.2, &lt; 1.10.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/langflow--1.7.2--1.10.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:44:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/langflow--1.7.2--1.10.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Langflow Insecure Credential Encryption and Key Derivation</title><link>https://feed.craftedsignal.io/briefs/2026-10-langflow-weak-fernet/</link><pubDate>Tue, 06 Oct 2026 00:44:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-langflow-weak-fernet/</guid><description>Langflow versions 1.10.0 and earlier use a non-cryptographic PRNG to derive Fernet keys from short SECRET_KEYs, allowing unauthenticated attackers who obtain the secret key file to perform offline decryption of all stored user credentials.</description><content:encoded><![CDATA[<p>Langflow versions 1.10.0 and earlier contain a critical cryptographic vulnerability in the handling of Fernet encryption keys used for storing sensitive user credentials, such as LLM API keys and database passwords. The application's <code>_ensure_valid_key</code> function incorrectly utilizes Python's non-cryptographic <code>random</code> module (Mersenne Twister) seeded with the instance's <code>SECRET_KEY</code> when that key is shorter than 32 characters. Because this process is fully deterministic, an attacker who obtains the <code>secret_key</code> file can recreate the encryption key offline without brute force. Furthermore, even when the <code>SECRET_KEY</code> is 32 characters or longer, the application uses the raw key directly as the Fernet key. This flaw is particularly dangerous when paired with file-read vulnerabilities, such as the MCP path traversal, which allow unauthorized access to the <code>secret_key</code> file and the underlying SQLite database. Once these files are exfiltrated, an attacker can decrypt all stored <code>Credential</code>-type variables across the entire instance.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target Langflow instance (v1.10.0 or earlier).</li>
<li>Attacker leverages an auxiliary vulnerability, such as MCP path traversal (GHSA-95rw-c7w3-xh7f), to bypass access controls.</li>
<li>Attacker exfiltrates the configuration file located at <code>/app/data/.cache/langflow/secret_key</code>.</li>
<li>Attacker exfiltrates the application database file <code>langflow.db</code> using the same file-read primitive.</li>
<li>Attacker checks the length of the exfiltrated <code>secret_key</code> to determine if the PRNG branch or raw-key branch applies.</li>
<li>Attacker executes an offline decryption script using the recovered <code>secret_key</code> and the extracted ciphertext from the <code>variable</code> table.</li>
<li>Attacker successfully recovers all stored API keys, database passwords, and OAuth tokens for all users on the instance.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the complete compromise of all stored credentials on a Langflow instance. This includes sensitive third-party API keys (OpenAI, Anthropic), database connection strings, and webhook secrets. In multi-tenant environments, this vulnerability permits a single attacker with low-level privileges to exfiltrate every credential stored by every user on the platform. The decryption process is entirely offline, ensuring the attacker leaves no server-side log traces during the credential recovery phase.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade Langflow to version 1.10.1 or later immediately to implement secure SHA-256 key derivation and mitigate the weak PRNG issue.</li>
<li>Rotate all API keys, database passwords, and other credentials previously stored in any Langflow instance that was running an affected version.</li>
<li>Inspect file access logs for unauthorized attempts to read the <code>/app/data/.cache/langflow/</code> directory or the <code>langflow.db</code> file to identify potential prior exploitation.</li>
<li>Ensure that the <code>SECRET_KEY</code> is set to a cryptographically secure random string of at least 32 characters to align with updated security requirements.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>credential-access</category><category>vulnerability</category><category>langflow</category><category>remote-code-execution</category><category>injection</category><category>ai-security</category><category>mcp</category><category>configuration-write</category><category>webserver</category><category>idor</category><category>data-disclosure</category></item></channel></rss>