peter bassill · operator
$ cve CVE-2026-0770 JSON

CVE-2026-0770 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 63.8% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2026-07-24.

Description

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS63.84% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-829
On CISA KEVyes — remediate by 2026-07-24
Public exploityes
Published2026-01-23
Last modified2026-07-22

CISA KEV

NameLangflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Added2026-07-21
Due2026-07-24
Vendor / productLangflow / Langflow
Ransomware usenone reported

Affected (1)

VendorProduct
langflowlangflow

Public exploits

SourceTitleDate
exploit-dbLangflow 1.3.0 - Remote Code Execution2026-05-29

References

→ the Explorer  ·  watch your stack  ·  NVD