ZeroHour
Security Affairspublished ()ingested @securityaffairs1

Hackers Target Langflow in CVE-2026

highExploit / PoC exploited in the wildimportance 72CVE-2026-0768
AI summary · glm-5.3-flash

Threat actors are actively exploiting CVE-2026-0768, an unauthenticated Python RCE in Langflow, hunting OpenAI, AWS, and SSH credentials.

Attackers began exploiting CVE-2026-0768 (CVSS 9.8), an unauthenticated remote code execution flaw in the code validator of the Langflow AI low-code platform, affecting all versions up to 1.4.2. VulnCheck observed 50+ Canary detections on the first day of exploitation, with attackers checking Langflow, OpenAI, and AWS keys in environment variables, reading the secret key, and looking for SSH access and shell history; most traffic originates from Russia and targeted UK-based canaries. The flaw was reported via ZDI by Trend Research in July 2025 and disclosed in January 2026; six other Langflow CVEs were added to VulnCheck's KEV list this year.

  • CVE-2026-0768 allows unauthenticated arbitrary Python execution in the context of root on Langflow <= 1.4.2
  • VulnCheck canaries logged 50+ first-time exploitation detections within hours
  • Attackers conduct reconnaissance and harvest credentials from environment variables and shell history
  • Exploit code, scanners, and Suricata/Snort rules are available from VulnCheck
  • Six other Langflow CVEs were added to VulnCheck's KEV list this year

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-0768
Langflow code Code Injection Remote Code Execution Vulnerability.

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-27322.

NVD description · AI analysis pending
9.82%
  • langflow langflow
Full article388 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 02, 2026

Hackers are exploiting a critical Langflow flaw that lets unauthenticated attackers remotely execute Python code on vulnerable systems.

Hackers have started exploiting a critical vulnerability, tracked as CVE-2026-0768 (CVSS score of 9.8), in the AI-focused low-code platform Langflow. The flaw affects the code validator in Langflow’s custom component editor, it impacts all Langflow versions up to version 1.4.2. Attackers do not need to authenticate to exploit it and can remotely execute arbitrary Python code.

“Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint.” reads the advisory. “The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root.”

Peter Girnus (@gothburz), William Gamazo Sanchez, and Alfredo Oliveira of Trend Research reported the issue through ZDI in July 2025. The flaw was publicly disclosed in January 2026.

VulnCheck researchers warns that threat actors are already targeting vulnerable Langflow instances, urging organizations to apply available fixes as soon as possible.

“A few hours ago, VulnCheck Canaries began observing first-time exploitation of CVE-2026-0768 in Langflow, a popular low-code platform for building AI-powered applications and workflows.” Caitlin Condon, VP at VulnCheck wrote on LinkedIn. “There are no known public PoCs for the vulnerability, which was disclosed in January through ZDI. We’ve seen 50+ Canary detections for CVE-2026-0768 so far this morning.”

Attackers appear to be carrying out reconnaissance and stealing credentials. They are checking environment variables such as Langflow, OpenAI and AWS keys, reading Langflow’s secret key, and looking for SSH access and shell history. The researchers state that most of the traffic comes from Russia and has so far targeted only UK-based Canaries.

Six other Langflow CVEs have been added to VulnCheck’s KEV list this year. VulnCheck also reports active threat activity targeting Langflow flaws through its Canaries.

For CVE-2026-0768, customers can access exploit code, scanners and Suricata/Snort rules, while Canary Intelligence users can see payloads, requests and attacker IPs.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Langflow)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/198270/hacking/hackers-target-langflow-in-cve-2026-0768-attacks.html