Langflow RCE: 34 minutes to server compromise
ID: 64cea485-f71b-528e-a5d6-10b3e8d57590
STIX ID: report--64cea485-f71b-528e-a5d6-10b3e8d57590
Feed Name: Bitbison Blog
### Langflow RCE (CVE-2026-9198): active in-the-wild exploitation — This analysis documents an unauthenticated RCE affecting default Langflow OSS (≤1.10.0) with auto-login exposed; researchers observed 12 of 18 exposure windows with code execution, credential exfiltration (including planted OpenAI keys), and multiple malware campaigns (XMRig miners, AdaptixC2 implant, Mirai-like bot). Defenders are advised to upgrade to 1.10.1+, search logs for /api/v1/auto_login followed by /api/v1/validate/code or GET /api/v1/flows from untrusted sources, rotate exposed credentials, investigate deleted-but-running executables, and rebuild contained systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
