Vulnary
← back to the feed
Critical· 9.8actively exploited

CVE-2026-0770

A critical flaw in Langflow’s validate endpoint allows attackers to run arbitrary code on the server without authentication. By sending a crafted exec_globals parameter, a remote user can execute code with root privileges. The vulnerability is present in Langflow version 1.4.2.

publishedJan 23, 2026
last modifiedJul 22, 2026
sourcesNVD · CISA-KEV
severity · cvss
9.8
critical · how bad it is
exploitation · epss
56%
99th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 4, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Langflow 1.4.2 installations that expose the validate endpoint to the internet.

02

Real-world impact

An attacker could take full control of the affected server, install malware, exfiltrate data, or use the machine as a launchpad for further attacks.

03

Why this severity

The CVSS score of 9.8 reflects that the flaw can be exploited over the network, requires no authentication, and grants complete control over confidentiality, integrity, and availability of the system.

04

What to do about it

no official fix yet
interim mitigations
  • Apply mitigations following the vendor’s instructions as outlined by CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk and Forensics Triage Requirements.
  • If mitigations are not available, consider discontinuing use of Langflow or restricting the validate endpoint to trusted networks.
  • Evaluate each exposed asset’s internet exposure and ensure compliance with BOD 26‑04 patching guidelines.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

CISA KEV required action

05

Timeline

  1. Jan 23, 2026 · Jan 23, 2026
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 21, 2026 · 16d ago
    Confirmed exploited (CISA KEV)
    CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
  3. Jul 22, 2026 · 14d ago
    Advisory updated
    The NVD record was last revised.
  4. Jul 24, 2026 · 13d ago
    CISA remediation deadline
    Federal agencies are required to remediate by this date.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →