Remote Code Execution Vulnerability in Langflow by Unknown Vendor
CVE-2026-0768

9.8CRITICAL

Key Information:

Vendor

Langflow

Status
Vendor
CVE Published:
23 January 2026

Badges

πŸ“ˆ Score: 173πŸ‘Ύ Exploit Exists🟑 Public PoCπŸ“° News Worthy

What is CVE-2026-0768?

CVE-2026-0768 represents a critical vulnerability found in Langflow, a software solution developed by an unknown vendor, designed primarily for facilitating specific workflows through programmable code integration. This vulnerability arises from inadequate validation of user-supplied input on the validate endpoint, specifically concerning the execution of Python code. Because the flaw allows remote attackers to execute arbitrary code without any requisite authentication, organizations utilizing Langflow are at significant risk. An attacker could exploit this vulnerability to gain root-level access, potentially leading to unauthorized data changes, malware deployment, and significant operational disruption.

Potential impact of CVE-2026-0768

  1. Unauthorized Code Execution: The vulnerability allows remote attackers to execute arbitrary Python code on affected Langflow installations, leading to potential system takeover and unauthorized access to sensitive data.

  2. Increased Attack Surface: As there is no authentication required to exploit this vulnerability, it opens the door for widespread attacks, increasing the likelihood of exploitation across various installations, especially those that are publicly accessible.

  3. Operational Disruption: Given that the vulnerability permits an attacker to execute code in the context of root, this could result in severe operational disruptions, including service outages, data loss, and significant recovery costs as organizations attempt to mitigate the damage caused by any exploited instance.

Affected Version(s)

Langflow 1.4.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Critical Langflow Flaw Exploited as Attacks on AI Platform Rise

The attacks on CVE-2026-0768 are the latest threats against the low-code AI development platform, which adversaries are flocking to this year.

2 weeks ago

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys.

2 weeks ago

References

CVSS V3.0

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by BleepingComputer

  • Vulnerability published

  • Vulnerability Reserved

.