CVE-2026-0768
Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-27322.
Preaviso: explotación observada
- Explotación observada desde el 29 ago 2026
- Todavía no está en el catálogo oficial de CISA
- Primer ataque observado 218 días después de la divulgación
- Confirmada por sensores, no solo por informes
Fuente: VulnCheck KEV · 2 sept 2026 1 sept 2026 30 ago 2026 30 ago 2026 29 ago 2026 29 ago 2026
Puntuación CVSS9.8 / 10
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTipo de debilidad (CWE)CWE-94
Fabricanteslangflow
Productos afectados
| Fabricantes | Prodotto | Versioni |
|---|---|---|
| langflow | langflow | 1.4.2 |
Artículos relacionados
This product uses the NVD API but is not endorsed or certified by the NVD.
