HACKERS are exploiting a critical vulnerability in the Langflow platform, identified as CVE-2026-0768, which allows unauthenticated attackers to remotely execute arbitrary Python code. This flaw, with a CVSS score of 9.8, affects all Langflow versions up to 1.4.2 and involves inadequate validation in the code parameter handling of the validate endpoint.
Initially reported in July 2025 and disclosed in January 2026, the vulnerability has seen active exploitation, mainly from Russian attackers targeting UK-based systems. Organizations using Langflow are urged to apply patches promptly, as exploit activity is documented. Vulnerable instances are at risk of reconnaissance and credential theft, making immediate action critical for security.