S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Feb 22, 2026

CVE-2026-0770 Scanner

CVE-2026-0770 Scanner - Remote Code Execution (RCE) vulnerability in Langflow

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.7k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2026-0770
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Langflowby Langflow
1.4.2
Updated Sep 9, 2026View on NVD →
Detail

Langflow is an AI workflow management tool used by developers and data scientists to streamline integration and management of AI models in applications. Companies and institutions employing AI-driven solutions for data processing and analysis make significant use of Langflow due to its robust features for AI workflow automation. Langflow enables a seamless interface for connecting AI models to business processes, thus facilitating enhanced decision-making and operational efficiency. Users leverage Langflow's capabilities to design, manage, and deploy workflows with AI model efficiency and collaboration in mind. The platform's robust API set allows for versatile integrations with various AI tools, making it a popular choice among AI researchers and developers. Generally, Langflow's efficient management capabilities provide organizations a centralized solution for their AI workflow needs.

The vulnerability in Langflow involves a Remote Code Execution (RCE) flaw caused by improper handling of code execution in the validate_code() function. It occurs when the application incorrectly trusts the exec_globals parameter from an untrusted control sphere. This ends up allowing remote attackers to execute arbitrary code, given the right payloads, thereby gaining unauthorized control. The execution is effortless given there is no prerequisite for authentication before exploiting this vulnerability. Ultimately, this flaw poses a severe risk by paving the way for potential full system compromises, especially when unauthorized actors can execute such vulnerabilities. It is imperative for Langflow operators to understand the ramifications of this oversight and proceed accordingly.

The technical details of this vulnerability reveal that the issue traces back to the exec_globals parameter being manipulated at the /api/v1/validate/code endpoint. Attackers can inject code through specially crafted payloads which Langflow, under certain configurations, incorrectly executes. Specifically, the validate_code endpoint inadvertently permits arbitrary code inclusion if not properly sanitized, allowing attackers an execution path directly to the system's core functionalities. With this oversight, attackers craft payloads that trick the endpoint into leveraging Python's eval or exec functions maliciously. As the vulnerability is unauthenticated, it directly exposes the system without initial access barriers. This open gateway is ripe for exploitation, leading to detrimental impacts if not corrected promptly.

When exploited, this vulnerability allows adversaries to carry out potentially disastrous actions like altering system settings or elevating privileges unwarrantedly. The ability to execute code as root enables attackers to takeover core system functions, paving the way for serious breaches. Adversaries can create, delete, or manipulate files and processes, rendering them capable of causing widespread system disruption. Data integrity, confidentiality, and availability are all at serious risk under these circumstances as the attacker has the potential to install and remove software, enabling backdoor entries or persistent malicious presence. Such exploits often lead to complete system compromises and data breaches, requiring urgent attention and last-minute patching efforts to prevent damage.

REFERENCES

Solution Advice
  • Update Langflow to version 1.3.0 or later to mitigate this vulnerability.
  • Implement strict input validation to ensure that exec and eval functions are not executed on untrusted input.
  • Consider employing application whitelisting to prevent unauthorized code execution within the environment.
  • Regularly monitor systems for unusual activities that may indicate exploitation attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.