{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/langflow-base--0.10.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-9205"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Langflow (\u003c= 1.10.0)","langflow (\u003e= 1.7.2, \u003c 1.10.1)","Langflow (\u003e= 1.3.0, \u003c 1.10.3)","Langflow (\u003e= 1.5.0, \u003c 1.10.3)","langflow (\u003c 1.10.3)","langflow-base (\u003c 0.10.3)","lfx (\u003c 1.10.3)","Langflow (\u003e= 1.6.8, \u003c= 1.9.0)"],"_cs_severities":["critical"],"_cs_tags":["credential-access","vulnerability","langflow","remote-code-execution","injection","ai-security","mcp","configuration-write","webserver","idor","data-disclosure"],"_cs_type":"advisory","_cs_vendors":["Langflow"],"content_html":"\u003cp\u003eLangflow versions 1.10.0 and earlier contain a critical cryptographic vulnerability in the handling of Fernet encryption keys used for storing sensitive user credentials, such as LLM API keys and database passwords. The application's \u003ccode\u003e_ensure_valid_key\u003c/code\u003e function incorrectly utilizes Python's non-cryptographic \u003ccode\u003erandom\u003c/code\u003e module (Mersenne Twister) seeded with the instance's \u003ccode\u003eSECRET_KEY\u003c/code\u003e when that key is shorter than 32 characters. Because this process is fully deterministic, an attacker who obtains the \u003ccode\u003esecret_key\u003c/code\u003e file can recreate the encryption key offline without brute force. Furthermore, even when the \u003ccode\u003eSECRET_KEY\u003c/code\u003e is 32 characters or longer, the application uses the raw key directly as the Fernet key. This flaw is particularly dangerous when paired with file-read vulnerabilities, such as the MCP path traversal, which allow unauthorized access to the \u003ccode\u003esecret_key\u003c/code\u003e file and the underlying SQLite database. Once these files are exfiltrated, an attacker can decrypt all stored \u003ccode\u003eCredential\u003c/code\u003e-type variables across the entire instance.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target Langflow instance (v1.10.0 or earlier).\u003c/li\u003e\n\u003cli\u003eAttacker leverages an auxiliary vulnerability, such as MCP path traversal (GHSA-95rw-c7w3-xh7f), to bypass access controls.\u003c/li\u003e\n\u003cli\u003eAttacker exfiltrates the configuration file located at \u003ccode\u003e/app/data/.cache/langflow/secret_key\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker exfiltrates the application database file \u003ccode\u003elangflow.db\u003c/code\u003e using the same file-read primitive.\u003c/li\u003e\n\u003cli\u003eAttacker checks the length of the exfiltrated \u003ccode\u003esecret_key\u003c/code\u003e to determine if the PRNG branch or raw-key branch applies.\u003c/li\u003e\n\u003cli\u003eAttacker executes an offline decryption script using the recovered \u003ccode\u003esecret_key\u003c/code\u003e and the extracted ciphertext from the \u003ccode\u003evariable\u003c/code\u003e table.\u003c/li\u003e\n\u003cli\u003eAttacker successfully recovers all stored API keys, database passwords, and OAuth tokens for all users on the instance.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the complete compromise of all stored credentials on a Langflow instance. This includes sensitive third-party API keys (OpenAI, Anthropic), database connection strings, and webhook secrets. In multi-tenant environments, this vulnerability permits a single attacker with low-level privileges to exfiltrate every credential stored by every user on the platform. The decryption process is entirely offline, ensuring the attacker leaves no server-side log traces during the credential recovery phase.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Langflow to version 1.10.1 or later immediately to implement secure SHA-256 key derivation and mitigate the weak PRNG issue.\u003c/li\u003e\n\u003cli\u003eRotate all API keys, database passwords, and other credentials previously stored in any Langflow instance that was running an affected version.\u003c/li\u003e\n\u003cli\u003eInspect file access logs for unauthorized attempts to read the \u003ccode\u003e/app/data/.cache/langflow/\u003c/code\u003e directory or the \u003ccode\u003elangflow.db\u003c/code\u003e file to identify potential prior exploitation.\u003c/li\u003e\n\u003cli\u003eEnsure that the \u003ccode\u003eSECRET_KEY\u003c/code\u003e is set to a cryptographically secure random string of at least 32 characters to align with updated security requirements.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-07T22:48:54Z","date_published":"2026-10-06T00:44:45Z","id":"https://feed.craftedsignal.io/briefs/2026-10-langflow-weak-fernet/","summary":"Langflow versions 1.10.0 and earlier use a non-cryptographic PRNG to derive Fernet keys from short SECRET_KEYs, allowing unauthenticated attackers who obtain the secret key file to perform offline decryption of all stored user credentials.","title":"Langflow Insecure Credential Encryption and Key Derivation","url":"https://feed.craftedsignal.io/briefs/2026-10-langflow-weak-fernet/"}],"language":"en","title":"CraftedSignal Threat Feed - Langflow-Base (\u003c 0.10.3)","version":"https://jsonfeed.org/version/1.1"}