CVE Explorer
CVE-2026-0770
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can le
Known exploited
CISA KEV
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"Langflow","vendor":"Langflow","versions":[{"status":"affected","version":"1.4.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ce4179eb8e17dd8d84f433b44bdc068d90ad7e88715a70b9a0d281522e8eb305 · sha256:ac4acc21cb7a48ee… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.0"},"metric_type":"cvssV3_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ce4179eb8e17dd8d84f433b44bdc068d90ad7e88715a70b9a0d281522e8eb305 · sha256:ac4acc21cb7a48ee… · /containers/cna/metrics/0/cvssV3_0
CWE assertions
1 source assertion{"cweId":"CWE-829","description":"CWE-829: Inclusion of Functionality from Untrusted Control Sphere","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ce4179eb8e17dd8d84f433b44bdc068d90ad7e88715a70b9a0d281522e8eb305 · sha256:ac4acc21cb7a48ee… · /containers/cna/problemTypes/0/descriptions/0
Known exploitation assertions
2 source assertions{"cwes":["CWE-829"],"dateAdded":"2026-07-21","dueDate":"2026-07-24","knownRansomwareCampaignUse":"Unknown","notes":"https://github.com/langflow-ai/langflow/releases/tag/v1.9.0 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-0770 ","product":"Langflow","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring complia…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:40c0ae12668ce5295fc0ca0562ea1f75889d757bef33d4f1c5bf974127e7c292 · sha256:635dff916c4092c0… · /vulnerabilities/11Open source location →
{"cwes":["CWE-829"],"dateAdded":"2026-07-21","dueDate":"2026-07-24","knownRansomwareCampaignUse":"Unknown","notes":"https://github.com/langflow-ai/langflow/releases/tag/v1.9.0 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-0770 ","product":"Langflow","requiredAction":"Apply mitigations in accordance with vendor instructions, ensuring complia…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:73de7610f8775ba73ff2489de648506eb662d33032adfb2d1a1a3c3eb9a42944 · sha256:16acee8334e59e44… · /vulnerabilities/8Open source location →
Source references
2 source assertions{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0770"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ce4179eb8e17dd8d84f433b44bdc068d90ad7e88715a70b9a0d281522e8eb305 · sha256:ac4acc21cb7a48ee… · /containers/adp/0/references/0
{"name":"ZDI-26-036","tags":["x_research-advisory"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-26-036/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ce4179eb8e17dd8d84f433b44bdc068d90ad7e88715a70b9a0d281522e8eb305 · sha256:ac4acc21cb7a48ee… · /containers/cna/references/0
Attribution and limitations
- CISA Known Exploited Vulnerabilities JSON: CISA named for provenance; do not use CISA/DHS marks or imply endorsement Source →
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.