CVE-2026-0768

CRITICAL9.8Pubblicata il 23 gennaio 2026

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-27322.

Preallarme: sfruttamento osservato

  • Sfruttamento osservato dal 29 ago 2026
  • Non ancora nel catalogo ufficiale CISA
  • Primo attacco osservato 218 giorni dopo la divulgazione
  • Confermata dai sensori, non solo da segnalazioni

Fonte: VulnCheck KEV · 1 set 2026 30 ago 2026 30 ago 2026 29 ago 2026 29 ago 2026

Punteggio CVSS9.8 / 10CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Tipo di debolezza (CWE)CWE-94
Vendorlangflow

Prodotti coinvolti

VendorProdottoVersioni
langflowlangflow1.4.2

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

Database CVE