Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3435 articles · 210641 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-0770KEVEXPLOITED
langflow · langflow

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability

Description

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.

Affected Products

VendorProductVersions
langflowlangflow1.4.2

References

  • https://www.zerodayinitiative.com/advisories/ZDI-26-036/(x_research-advisory)
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-0770.yaml(exploit, nuclei)

Related News (5 articles)

Tier D
BleepingComputer31d ago
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
→ No new info (linked only)
Tier B
CERT-FR41d ago
Bulletin d'actualité CERTFR-2026-ACT-032 (27 juillet 2026)
→ No new info (linked only)
Tier D
BleepingComputer45d ago
CISA orders urgent action on actively exploited Langflow RCE flaw
→ No new info (linked only)
Tier E
Reddit r/cybersecurity98d ago
PAN-OS added to KEV, Langflow exploit activity, and a surprising Windows EPSS jump — today's most actionable vulnerability signals [Threat Intel 2026/5/29}
→ No new info (linked only)
Tier C
Exploit-DB100d ago
[webapps] Langflow 1.3.0 - Remote Code Execution
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
CWECWE-829
PublishedJan 23, 2026
Last enriched45d agov3
Tags
CISA-KEVin-the-wildmalware-deploymentcredential-theft
Trending Score2
Source articles5
Independent4
Info Completeness10/14
Missing: epss, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-9198EXPKEV
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
Trending: 93
HIGHCVE-2026-17632
Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
Trending: 2
HIGHCVE-2026-9196
Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
Trending: 2
HIGHCVE-2026-9205
Langflow is affected by weaknesses in secret handling and sensitive configuration access
Trending: 2
HIGHCVE-2026-9201
Langflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handling
Trending: 2

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Jan 23, 2026
Added to CISA KEV
Jan 23, 2026
Discovered by ZDM
Apr 1, 2026
Updated: affectedVersions
May 29, 2026
Actively Exploited
Jul 22, 2026
Exploit Available
Jul 22, 2026
Updated: tags
Jul 22, 2026

Version History

v3
Last enriched 45d ago
v3Tier D45d ago

Added tags indicating CISA KEV catalog inclusion, in-the-wild exploitation details including malware deployment attempts and credential theft objectives, and the specific exploitation endpoint /api/v1/validate/code.

tags
via BleepingComputer
v2Tier C99d ago

Updated description with more technical detail, added affected version 1.2.0, and marked exploit as available.

affectedVersions
via Exploit-DB
v1157d ago

Initial creation