Langflow Disk Cache Unauthenticated Remote Code Execution Vulnerability
CVE-2026-0772
7.5HIGH
What is CVE-2026-0772?
The Langflow application contains a vulnerability related to its disk cache service, which fails to properly validate user-supplied data. This oversight allows remote attackers, with necessary authentication, to exploit the deserialization of untrusted data. By leveraging this flaw, attackers can execute arbitrary code within the context of the service account, potentially compromising the security of the entire system.
Affected Version(s)
Langflow 1.5.0.post2
