logo

Langflow RCE: 34 minutes to server compromise

ID: 64cea485-f71b-528e-a5d6-10b3e8d57590

STIX ID: report--64cea485-f71b-528e-a5d6-10b3e8d57590

Feed Name: Bitbison Blog

Threat Score
76/100

Date Published: 2026-08-19

Date Updated: 2026-08-21

...
...

### Langflow RCE (CVE-2026-9198): active in-the-wild exploitation — This analysis documents an unauthenticated RCE affecting default Langflow OSS (≤1.10.0) with auto-login exposed; researchers observed 12 of 18 exposure windows with code execution, credential exfiltration (including planted OpenAI keys), and multiple malware campaigns (XMRig miners, AdaptixC2 implant, Mirai-like bot). Defenders are advised to upgrade to 1.10.1+, search logs for /api/v1/auto_login followed by /api/v1/validate/code or GET /api/v1/flows from untrusted sources, rotate exposed credentials, investigate deleted-but-running executables, and rebuild contained systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.