Vulnerability
Published 2026-01-09
Verified 2026-09-19

Langflow unauthenticated code injection exploited (CVE-2026-0768); credential harvest on honeypots

Trend Micro ZDI advisory ZDI-26-034 (public 9 January 2026; CVE-2026-0768) rates an unauthenticated code-injection flaw in Langflow at CVSS 9.8: the validate endpoint executes a user-supplied code string as Python, which ZDI says can run as root. NVD published the CVE on 23 January 2026 and records affected Langflow 1.4.2. On 1 September 2026 VulnCheck told BleepingComputer and SecurityWeek it had seen exploitation against U.K. honeypots over the prior weekend (about 50 attempts at first report, later more than 360), mainly from Russia, with attackers querying LANGFLOW_SUPERUSER, OPENAI_API*, AWS_ACCESS* and AWS_SECRET* environment variables and reading Langflow secret material. Distinct from desk card cve-2026-9198 (separate Langflow code-injection CVE on CISA KEV). ZDI's published mitigation is to restrict interaction with the product; this desk does not invent a single fixed build number for CVE-2026-0768. Do not internet-expose unauthenticated Langflow.

Product
Langflow
Versions
NVD/ZDI record Langflow 1.4.2 affected; confirm your installed build against current vendor releases
CVSS
(CVSS 3.0, ZDI)
Exploited in Australia?
unknown
Patch to
Restrict exposure of Langflow (ZDI); apply current vendor releases after verifying they address CVE-2026-0768

Primary: Trend Micro ZDI-26-034 (CVE-2026-0768) · Vendor: NVD (CVE-2026-0768) · CVE: CVE-2026-0768, CVE-2026-9198 · BleepingComputer (1 Sep 2026; VulnCheck)

tech ai cloud