CVE-2026-0770
A critical flaw in Langflow’s validate endpoint allows attackers to run arbitrary code on the server without authentication. By sending a crafted exec_globals parameter, a remote user can execute code with root privileges. The vulnerability is present in Langflow version 1.4.2.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Langflow 1.4.2 installations that expose the validate endpoint to the internet.
Real-world impact
An attacker could take full control of the affected server, install malware, exfiltrate data, or use the machine as a launchpad for further attacks.
Why this severity
The CVSS score of 9.8 reflects that the flaw can be exploited over the network, requires no authentication, and grants complete control over confidentiality, integrity, and availability of the system.
What to do about it
- ›Apply mitigations following the vendor’s instructions as outlined by CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk and Forensics Triage Requirements.
- ›If mitigations are not available, consider discontinuing use of Langflow or restricting the validate endpoint to trusted networks.
- ›Evaluate each exposed asset’s internet exposure and ensure compliance with BOD 26‑04 patching guidelines.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
CISA KEV required action
Timeline
- Jan 23, 2026 · Jan 23, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 16d agoConfirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jul 22, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.
- Jul 24, 2026 · 13d agoCISA remediation deadlineFederal agencies are required to remediate by this date.
How it’s attacked
References & advisories
- zerodayinitiative.com/advisories/ZDI-26-036/third party advisory
- cisa.gov/known-exploited-vulnerabili…us government resource