cve-2026-0768

CRITICAL CVSS 9.8 opencve
Description

Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-27322.

Timeline
Published
2026-01-23 04:16 UTC
Last Modified
2026-06-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.0 9.8 CRITICAL CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H mitre
3.0 9.8 CRITICAL CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H nvd
3.0 9.8 CRITICAL CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H opencve
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cve": "CVE-2026-0768",
  "enrichment": {
    "created": "2026-01-23T10:26:54.904307+00:00",
    "updated": "2026-09-21T08:30:13.130137+00:00",
    "vendors": [
      "langflow",
      "langflow$PRODUCT$langflow"
    ]
  },
  "epss": {
    "score": 0.08451
  },
  "mitre": {
    "cpes": [],
    "created": "2026-01-23T03:28:43.301000+00:00",
    "description": "Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root.\n. Was ZDI-CAN-27322.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {
        "score": 9.8,
        "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV3_1": {},
      "cvssV4_0": {}
    },
    "mitre_repo_path": "cves/2026/0xxx/CVE-2026-0768.json",
    "references": [
      "https://www.zerodayinitiative.com/advisories/ZDI-26-034/"
    ],
    "title": "Langflow code Code Injection Remote Code Execution Vulnerability",
    "updated": "2026-02-26T14:44:27.192000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-94"
    ]
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:a:langflow:langflow:1.4.2:-:*:*:*:*:*:*"
    ],
    "created": "2026-01-23T04:16:03.800000+00:00",
    "description": "Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root.\n. Was ZDI-CAN-27322.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {
        "score": 9.8,
        "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
      },
      "cvssV3_1": {},
      "cvssV4_0": {}
    },
    "nvd_repo_path": "2026/CVE-2026-0768.json",
    "references": [
      "https://www.zerodayinitiative.com/advisories/ZDI-26-034/"
    ],
    "title": null,
    "updated": "2026-06-17T10:11:20.937000+00:00",
    "vendors": [
      "langflow",
      "langflow$PRODUCT$langflow"
    ],
    "weaknesses": [
      "CWE-94"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-01-23T04:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root.\n. Was ZDI-CAN-27322.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "new": "Langflow code Code Injection Remote Code Execution Vulnerability",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-94"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "https://www.zerodayinitiative.com/advisories/ZDI-26-034/"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_0": {
                  "score": 9.8,
                  "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "772d9772-e6e0-4936-b380-d3f09ac54f39"
      },
      {
        "created": "2026-01-23T16:45:00+00:00",
        "data": [
          {
            "details": [
              "langflow",
              "langflow$PRODUCT$langflow"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "langflow",
                "langflow$PRODUCT$langflow"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "fa67390b-7917-4e9f-924e-09d646be9e6b"
      },
      {
        "created": "2026-01-23T17:15:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "yes",
                    "Exploitation": "none",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "19971d83-0387-40b9-86b3-248bb3384f90"
      },
      {
        "created": "2026-02-18T16:45:00+00:00",
        "data": [
          {
            "details": {
              "added": [
                "cpe:2.3:a:langflow:langflow:1.4.2:-:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          }
        ],
        "id": "315cc337-5778-415f-b2a8-57328c86ad28"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:langflow:langflow:1.4.2:-:*:*:*:*:*:*"
      ],
      "providers": [
        "nvd"
      ]
    },
    "created": {
      "data": "2026-01-23T03:28:43.301000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root.\n. Was ZDI-CAN-27322.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {
          "score": 9.8,
          "vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
        },
        "provider": "mitre"
      },
      "cvssV3_1": {
        "data": {},
        "provider": null
      },
      "cvssV4_0": {
        "data": {},
        "provider": null
      },
      "epss": {
        "data": {
          "score": 0.08451
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "yes",
            "Exploitation": "none",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://www.zerodayinitiative.com/advisories/ZDI-26-034/"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "Langflow code Code Injection Remote Code Execution Vulnerability",
      "provider": "mitre"
    },
    "updated": {
      "data": "2026-04-18T15:30:03.947035+00:00",
      "provider": "enrichment"
    },
    "vendors": {
      "data": [
        "langflow",
        "langflow$PRODUCT$langflow"
      ],
      "providers": [
        "nvd",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-94"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-01-23T03:28:43.301000+00:00",
    "description": "Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root.\n. Was ZDI-CAN-27322.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "yes",
          "Exploitation": "none",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": "Langflow code Code Injection Remote Code Execution Vulnerability",
    "updated": "2026-01-23T16:33:21.284000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/0xxx/CVE-2026-0768.json",
    "weaknesses": []
  }
}
Enrichment data
View JSON API Download JSON