PT-2026-2000 · Langflow · Langflow

Alfredo Oliveira

+3

·

Published

2026-01-09

·

Updated

2026-05-30

·

CVE-2026-0770

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Langflow (affected versions not specified)
Description A flaw exists in Langflow that allows remote attackers to execute arbitrary code. Authentication is not required for exploitation. The issue stems from the inclusion of functionality from an untrusted control sphere when handling the exec globals parameter provided to the validate endpoint. Successful exploitation allows an attacker to execute code in the context of root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-0770
GHSA-G22F-V6F7-2HRH
ZDI-26-036

Affected Products

Langflow