What is CVE-2026-0768?
Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-27322.
Timeline
- 2026-01-23Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-17NVD record last updated
- 2026-09-02First covered in a defend.network daily briefing
Affected product
Langflow
Remediation Steps
- Apply vendor patch for Langflow immediately
- Rotate all exposed credentials including OpenAI and AWS keys
- Restrict network access to Langflow instances to trusted networks only
- Monitor logs for indicators of unauthorized access or credential exfiltration
- Review and revoke any API tokens or access keys that may have been compromised
References
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 5 of August 2026 (August 31 – September 6)
- JFrog Artifactory, Langflow critical flaws exploited; TeamPCP arrested (2026-09-02)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.