Hackers Target Langflow in CVE-2026-0768 Attacks

Hackers Target Langflow in CVE-2026-0768 Attacks

Hackers Target Langflow in CVE-2026-0768 Attacks

Hackers Target Langflow in CVE-2026-0768 Attacks

Hackers Target Langflow in CVE-2026-0768 Attacks

Pierluigi Paganini
September 02, 2026

Hackers are exploiting a critical Langflow flaw that lets unauthenticated attackers remotely execute Python code on vulnerable systems.

Hackers have started exploiting a critical vulnerability, tracked as CVE-2026-0768 (CVSS score of 9.8), in the AI-focused low-code platform Langflow. The flaw affects the code validator in Langflow’s custom component editor, it impacts all Langflow versions up to version 1.4.2. Attackers do not need to authenticate to exploit it and can remotely execute arbitrary Python code.

“Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint.” reads the advisory. “The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root.”

Peter Girnus (@gothburz), William Gamazo Sanchez, and Alfredo Oliveira of Trend Research reported the issue through ZDI in July 2025. The flaw was publicly disclosed in January 2026.

VulnCheck researchers warns that threat actors are already targeting vulnerable Langflow instances, urging organizations to apply available fixes as soon as possible.

“A few hours ago, VulnCheck Canaries began observing first-time exploitation of CVE-2026-0768 in Langflow, a popular low-code platform for building AI-powered applications and workflows.” Caitlin Condon, VP at VulnCheck wrote on LinkedIn. “There are no known public PoCs for the vulnerability, which was disclosed in January through ZDI. We’ve seen 50+ Canary detections for CVE-2026-0768 so far this morning.”

Attackers appear to be carrying out reconnaissance and stealing credentials. They are checking environment variables such as Langflow, OpenAI and AWS keys, reading Langflow’s secret key, and looking for SSH access and shell history. The researchers state that most of the traffic comes from Russia and has so far targeted only UK-based Canaries.

Six other Langflow CVEs have been added to VulnCheck’s KEV list this year. VulnCheck also reports active threat activity targeting Langflow flaws through its Canaries.

For CVE-2026-0768, customers can access exploit code, scanners and Suricata/Snort rules, while Canary Intelligence users can see payloads, requests and attacker IPs.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Langflow)



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.