THREAT actors are exploiting a critical remote code execution (RCE) vulnerability in the AI low-code platform Langflow, identified as CVE-2026-0768, with a CVSS score of 9.8. This vulnerability occurs in the code validator of Langflow’s custom component editor, allowing attackers to execute arbitrary code as root without authentication due to improper validation of user-supplied strings.
VulnCheck reports that this flaw has led to over 360 exploitation attempts, primarily from Russia, with the vulnerability being actively used for reconnaissance and credential harvesting. All Langflow releases prior to version 1.4.2 are affected. The rapid increase in exploitation of Langflow vulnerabilities this year has raised concerns among cybersecurity professionals.