EXPOSURES › CVE-2026-0770
CVE-2026-0770
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
rceexploited-in-wildunpatched
Langflow RCE due to untrusted code execution
Langflow, an open-source AI workflow builder, included untrusted functionality that allowed remote attackers to execute arbitrary code, leading to potential data breaches and unauthorized access.
Shame score — Critical security risk profile with multiple actively exploited vulnerabilities.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.