logo

Exploiting Langflow's validate_code() Endpoint for Remote Code Execution

ID: ee30172a-5c2b-5caf-af60-cb7e4149c897

STIX ID: report--ee30172a-5c2b-5caf-af60-cb7e4149c897

Feed Name: Resecurity

Threat Score
95/100

Date Published: 2026-07-29

Date Updated: 2026-08-03

...
...

**CVE-2026-0770 — Critical unauthenticated RCE in Langflow**: An unsafe exec() call in Langflow's POST /api/v1/validate/code validation path allows crafted Python function definitions (via default arguments/decorators) to execute arbitrary OS commands; the flaw (CVSS 9.8) affected versions up to 1.7.3, was actively exploited in the wild from at least June 27, 2026, and is listed in CISA's KEV catalog — immediate actions include upgrading to the fixed release-1.10.1, assuming compromise for exposed instances, rotating credentials, and conducting a forensic investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.