CVE-2026-0770 is a critical remote code execution vulnerability affecting Langflow, specifically within the handling of the exec_globals parameter in the validate endpoint. This flaw allows unauthenticated remote attackers to execute arbitrary code with root privileges due to the inclusion of functionality from an untrusted control sphere. With a CVSS score of 9.8 (Critical), it presents a severe risk, requiring no user interaction or authentication for exploitation. While not currently on CISA's KEV catalog, a Nuclei template exists for versions prior to 1.3.0, indicating readily available exploit code, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.3CPE matchmatch criteria | cpe:2.3:a:langflow:langflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.