CVE-2026-0768

CRITICAL9.8Publicada el 23 de enero de 2026

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-27322.

Preaviso: explotación observada

  • Explotación observada desde el 29 ago 2026
  • Todavía no está en el catálogo oficial de CISA
  • Primer ataque observado 218 días después de la divulgación
  • Confirmada por sensores, no solo por informes

Fuente: VulnCheck KEV · 2 sept 2026 1 sept 2026 30 ago 2026 30 ago 2026 29 ago 2026 29 ago 2026

Puntuación CVSS9.8 / 10CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Tipo de debilidad (CWE)CWE-94
Fabricanteslangflow

Productos afectados

FabricantesProdottoVersioni
langflowlangflow1.4.2

Artículos relacionados

This product uses the NVD API but is not endorsed or certified by the NVD.

Base de datos CVE