Langflow unauthenticated code injection exploited (CVE-2026-0768); credential harvest on honeypots
Trend Micro ZDI advisory ZDI-26-034 (public 9 January 2026; CVE-2026-0768) rates an unauthenticated code-injection flaw in Langflow at CVSS 9.8: the validate endpoint executes a user-supplied code string as Python, which ZDI says can run as root. NVD published the CVE on 23 January 2026 and records affected Langflow 1.4.2. On 1 September 2026 VulnCheck told BleepingComputer and SecurityWeek it had seen exploitation against U.K. honeypots over the prior weekend (about 50 attempts at first report, later more than 360), mainly from Russia, with attackers querying LANGFLOW_SUPERUSER, OPENAI_API*, AWS_ACCESS* and AWS_SECRET* environment variables and reading Langflow secret material. Distinct from desk card cve-2026-9198 (separate Langflow code-injection CVE on CISA KEV). ZDI's published mitigation is to restrict interaction with the product; this desk does not invent a single fixed build number for CVE-2026-0768. Do not internet-expose unauthenticated Langflow.
- Product
- Langflow
- Versions
- NVD/ZDI record Langflow 1.4.2 affected; confirm your installed build against current vendor releases
- CVSS
- (CVSS 3.0, ZDI)
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Restrict exposure of Langflow (ZDI); apply current vendor releases after verifying they address CVE-2026-0768
Primary: Trend Micro ZDI-26-034 (CVE-2026-0768) · Vendor: NVD (CVE-2026-0768) · CVE: CVE-2026-0768, CVE-2026-9198 · BleepingComputer (1 Sep 2026; VulnCheck)
