Skip to content
COOEY

EXPOSURES › CVE-2026-0770

CVE-2026-0770

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-07-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-0770 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Langflow RCE due to untrusted code execution

Langflow, an open-source AI workflow builder, included untrusted functionality that allowed remote attackers to execute arbitrary code, leading to potential data breaches and unauthorized access.

Shame score — Critical security risk profile with multiple actively exploited vulnerabilities.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.