A critical, actively exploited flaw in Langflow lets unauthenticated remote attackers run arbitrary code as root through the validate endpoint's exec_globals parameter.
What Is It
CVE-2026-0770 is an Inclusion of Functionality from Untrusted Control Sphere vulnerability (CWE-829) in Langflow. The specific flaw exists in the handling of the exec_globals parameter provided to the validate endpoint, where a resource from an untrusted control sphere is included. This allows remote attackers to execute arbitrary code on affected installations. Authentication is not required to exploit it, and code executes in the context of root. It was disclosed through Trend Micro's Zero Day Initiative as ZDI-CAN-27325 (advisory ZDI-26-036).
Why It Matters
The vulnerability carries a CVSS 3.0 base score of 9.8 (CRITICAL), with the vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low complexity, no privileges, and no user interaction, with high confidentiality, integrity, and availability impact. CISA's SSVC assessment rates exploitation as "active," automatable as "yes," and technical impact as "total." CISA added it to the Known Exploited Vulnerabilities catalog on 2026-07-21, confirming active exploitation in the wild. Known ransomware campaign use is listed as Unknown.
What's Vulnerable
Langflow (product: Langflow, vendor: Langflow). NVD lists version 1.4.2 as affected, and because the vendor's fix ships in v1.9.0 (see Patch Status), all releases prior to 1.9.0 should be treated as vulnerable (cpe:2.3:a:langflow:langflow).
Patch Status
CISA's required action is to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 (Prioritizing Security Updates Based on Risk) guidance and CISA's "Forensics Triage Requirements." Organizations should follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable, and evaluate each asset's internet exposure. The remediation due date is 2026-07-24. The vendor addresses this issue in Langflow v1.9.0; upgrading to v1.9.0 or later resolves the flaw.
Sources
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0770
- NVD, CVE-2026-0770, https://nvd.nist.gov/vuln/detail/CVE-2026-0770
- Zero Day Initiative Advisory ZDI-26-036; https://www.zerodayinitiative.com/advisories/ZDI-26-036/
- Langflow v1.9.0 Release Notes; https://github.com/langflow-ai/langflow/releases/tag/v1.9.0
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk