Exploiting Langflow's validate_code() Endpoint for Remote Code Execution
ID: ee30172a-5c2b-5caf-af60-cb7e4149c897
STIX ID: report--ee30172a-5c2b-5caf-af60-cb7e4149c897
Feed Name: Resecurity
**CVE-2026-0770 — Critical unauthenticated RCE in Langflow**: An unsafe exec() call in Langflow's POST /api/v1/validate/code validation path allows crafted Python function definitions (via default arguments/decorators) to execute arbitrary OS commands; the flaw (CVSS 9.8) affected versions up to 1.7.3, was actively exploited in the wild from at least June 27, 2026, and is listed in CISA's KEV catalog — immediate actions include upgrading to the fixed release-1.10.1, assuming compromise for exposed instances, rotating credentials, and conducting a forensic investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
