CVE-2026-0770High▾ Abyssal⚠ Exploited in the wild0dayPoC availableLangflow affected by Remote Code Execution via validate_code() exec()
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 41.3 · likelihood 12.8 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
10%
Federal remediation due Jul 24, 2026
10% → 64%
Exploit-DB · 7 GitHub repos · Nuclei ×1 (last check)
Added to the CISA catalog on Jul 21, 2026. Federal remediation due Jul 24, 2026. View catalog ↗
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.
langflow <= 1.7.3Refer to the advisory for the patched release.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-34291High· 8.8Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution
CVE-2024-48061Critical· 9.8Langflow vulnerable to remote code execution
CVE-2026-6599Medium· 6.3Langflow vulnerable to injection
CVE-2026-6598Medium· 4.3Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
CVE-2026-34046HighLangflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
CVE-2026-6597Low· 2.7Langflow has an Information Leak through Incomplete API Key Redaction