Hackers Target Langflow in CVE-2026-0768 Attacks
Brief
Hackers are exploiting a critical Langflow flaw that lets unauthenticated attackers remotely execute Python code on vulnerable systems.
Hackers have started exploiting a critical vulnerability, tracked as CVE-2026-0768 (CVSS score of 9. 8), in the AI-focused low-code platform Langflow. The flaw affects the code validator in Langflow’s custom component editor, it impacts all Langflow versions up to version 1.
- 2. Attackers do not need to authenticate to exploit it and can remotely execute arbitrary Python code.
“Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint.” reads the advisory .
