CVE-2026-0768
CVSS 9.8 CRITICAL: langflow code Code Injection Remote Code Execution Vulnerability. EPSS 8% (95th percentile).
Vulnerabilities & Exploits · Web App Attack
VulnCheck saw continuous exploitation attempts against internet-facing Langflow instances starting August 29, after CVE-2026-0768 was disclosed as a critical code-injection flaw in the low-code AI app builder. The attacks have already been tied to credential harvesting.
The bug sits in Langflow's validation endpoint: it sends submitted code straight into Python's exec(), so a crafted request can run arbitrary Python as root, often without logging in first. Once inside, attackers can pull .env files, environment variables, SSH keys, API keys, cloud tokens, and database credentials, then reuse those secrets against connected systems.
For teams that let Langflow sit on the same host or network path as production credentials, the exposure does not end with the patch. The app becomes a secrets concentrator: compromise of the builder can spill into cloud, database, and AI service accounts that were never meant to be part of the application itself.
1 source · 5h ago
CVSS 9.8 CRITICAL: langflow code Code Injection Remote Code Execution Vulnerability. EPSS 8% (95th percentile).
CSO Online
The AI app builder your team trusts has a root-level backdoor
The next AI security disaster may not start with your model — it may start with the low-code tool your team trusted to build it.
originalPart of the PlainSec briefing for 2026-10-06
Every edition of this story: Langflow Exploitation Turns AI Builders Into Secret Vaults