Skip to main content
QUIETLYTIC
Vulnerability

Langflow Code Injection (CVE-2026-0768)

CVE-2026-0768 is a CVSS 9.8 code injection flaw in Langflow allowing unauthenticated remote code execution as root, reported exploited by VulnCheck KEV.

CVE-2026-0768
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
Langflow

CVE-2026-0768 carries a CVSS 3.0 base score of 9.8 against Langflow, an open-source visual builder for AI and LLM workflows. NVD classifies it as CWE-94 (Improper Control of Generation of Code) and states the flaw allows remote attackers to execute arbitrary code on affected installations without authentication. VulnCheck’s KEV feed reports the CVE as exploited, dated August 29, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-0768 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description, credited to the Zero Day Initiative (ZDI-CAN-27322), states the specific flaw exists in how Langflow’s validate endpoint handles a code parameter. The application accepts a user-supplied string and uses it to execute Python code without proper validation. Because the endpoint requires no authentication, per NVD, a remote attacker can submit crafted input directly and have it executed. NVD states the resulting code runs in the context of root — the highest privilege level on a Linux host — meaning successful exploitation compromises the entire host, not just the Langflow application’s own data.

Evidence and confidence

  • Medium confidence — the CVSS 9.8 score, the vector (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-94 classification, and the specific vulnerable endpoint and parameter (validate, code) all trace to NVD alone, which in turn credits the Zero Day Initiative’s original research. The exploitation report traces to VulnCheck KEV alone.
  • High exploitation probability — FIRST’s EPSS model scores this CVE at 0.07669, a 94.3rd percentile score as of our ingestion — among the higher scores we’ve seen in recent KEV coverage, consistent with an unauthenticated, low-complexity, root-level code execution flaw in a popular AI-tooling project.

No field is in conflict between our two sources. Our data carries no fixed-version field; NVD’s description does not name a version boundary.

Why this matters

Langflow is widely used to build and prototype AI/LLM application workflows, often run by developers and small teams standing up internal tools quickly — an environment where a server may be exposed with default or minimal hardening while the underlying flaw grants full root access, not merely access to the application itself. The combination of no authentication requirement, root-level impact, and a notably high EPSS score makes this one of the more urgent VulnCheck-only advisories in our recent coverage, on the strength of the technical facts alone.

Because NVD’s record gives no fixed-version boundary, operators cannot confirm safety by checking a version number against a stated cutoff the way they can for most of our other coverage this batch; the safest posture is to treat any exposed Langflow instance as vulnerable until the vendor’s own advisory or release notes state otherwise, and to restrict network access to the validate endpoint in the interim.

Frequently Asked Questions

What is CVE-2026-0768? A CVSS 9.8 code injection vulnerability (CWE-94) in Langflow, an AI/LLM workflow builder, allowing unauthenticated remote attackers to execute arbitrary Python code as root via the validate endpoint’s code parameter.

Is CVE-2026-0768 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 29, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.

How severe is the impact if exploited? NVD states the resulting code execution runs in the context of root — full host compromise, not just application-level access.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Is there a fixed version? Our data carries no fixed-version field, and NVD’s description does not name one. Check Langflow’s own release notes and security advisories directly, and restrict network access to the affected endpoint in the meantime.


Severity, vector, weakness classification, and the vulnerable endpoint/parameter sourced from the National Vulnerability Database record for CVE-2026-0768, which credits the Zero Day Initiative’s advisory ZDI-26-034. Exploitation status and the August 29, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools