Langflow, an open-source tool for building AI agents and workflows, has been flagged by CISA for a critical actively...
Langflow, an open-source tool for building AI agents and workflows, has been flagged by CISA for a critical actively exploited vulnerability (CVE-2026-0770) and added to the Known Exploited Vulnerabilities (KEV) catalog as of July 21, 2026, with a due date of July 24.
confidence score
Strong evidence: 3 independent source classes support this read.
signal brief
Langflow, an open-source tool for building AI agents and workflows, has been flagged by CISA for a critical actively exploited vulnerability (CVE-2026-0770) and added to the Known Exploited Vulnerabilities (KEV) catalog as of July 21, 2026, with a due date of July 24. This follows a flurry of other serious vulnerabilities disclosed in June and July 2026, including multiple remote code execution (RCE), IDOR, path traversal, and authentication bypass flaws (see OSV advisories PYSEC-2026-1521 through 1525, 221-224, 242-244, 376-379, 2565-2569). The cumulative disclosure signals that Langflow's codebase has systemic security weaknesses, especially around the Shareable Playground and public flow endpoints. The CISA KEV listing confirms active exploitation, which likely undermines enterprise trust and may slow adoption for production AI workflows. Organizations are required to patch by July 24 or discontinue use under BOD 26-04. The PyPI release of version 1.12.0.dev0 on July 22 suggests ongoing development, but the security posture remains a concern.
What the sources said:
- CISA KEV: "Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations." (https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-0770)
- OSV advisory PYSEC-2026-378: "Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit" (https://osv.dev/vulnerability/PYSEC-2026-378)
- OSV advisory PYSEC-2026-243: "Langflow...contains a critical RCE vulnerability. Shareable Playground...execution of workflows by unauthenticated users." (https://osv.dev/vulnerability/PYSEC-2026-243)
- OSV advisory PYSEC-2026-242: "Any authenticated user can read, modify, rename, or permanently delete another user's data by supplying the target's resource ID or flow_id." (https://osv.dev/vulnerability/PYSEC-2026-242)
source data used
“CVE: CVE-2026-0770 Vendor/project: Langflow Product: Langflow Known ransomware campaign use: Unknown Due date: 2026-07-24 CWE: CWE-829 Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on...”
“A Python package with a built-in web application”
“Aliases: CVE-2024-9277, GHSA-355v-2rjx-fpx7 Inefficient Regular Expression Complexity in langflow”
“Aliases: CVE-2025-68477, GHSA-5993-7p27-66g5 Langflow vulnerable to Server-Side Request Forgery”
“Aliases: CVE-2024-48061, GHSA-5p5r-57fx-pmfr Langflow vulnerable to remote code execution”
“Aliases: CVE-2026-21445, GHSA-c5cp-vx83-jhqx, PYSEC-2026-2571 Langflow Missing Authentication on Critical API Endpoints”
“Aliases: CVE-2026-0770, GHSA-g22f-v6f7-2hrh Langflow affected by Remote Code Execution via validate_code() exec()”
“Aliases: CVE-2026-55255, GHSA-qrpv-q767-xqq2 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow...”
“Aliases: CVE-2026-55423, GHSA-7hw8-6q6r-4276 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly...”
“Aliases: CVE-2026-55446, GHSA-qwqc-p3q8-wcg9 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request without any authentication token/cookies and abuse a very long multipart form...”
“Aliases: CVE-2026-55450, GHSA-x223-p2gf-v735 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any...”
“Aliases: CVE-2026-33760, GHSA-9c59-2mvc-vfr8 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints that perform read, write, and delete operations on user-owned resources — messages,...”
“Aliases: CVE-2026-48519, GHSA-v5ff-9q35-q26f Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical RCE vulnerability. Shareable Playground feature works by...”
“Aliases: CVE-2026-48520, GHSA-rcjh-r59h-gq37 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code) contains a potential arbitrary file-read vulnerability, depending on the exact...”
“Aliases: CVE-2026-6597, GHSA-5jjf-wcvf-923w Langflow has an Information Leak through Incomplete API Key Redaction”
“Aliases: CVE-2026-42867, GHSA-79ph-745m-6wxq Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint”
“Aliases: CVE-2026-34046, GHSA-8c4j-f57c-35cf, PYSEC-2026-2570 Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check”
“Aliases: CVE-2026-6598, GHSA-9jpj-cph8-w449 Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint”
“Aliases: CVE-2026-6599, GHSA-v66p-f7x3-4794 Langflow vulnerable to injection”
“Aliases: CVE-2026-27966, GHSA-3645-fxcv-hqr4 Langflow has Remote Code Execution in CSV Agent”
“Aliases: CVE-2026-42048, GHSA-9whx-c884-c68q Langflow Knowledge Bases API is Vulnerable to Path Traversal”
“Aliases: CVE-2026-55447, GHSA-ccv6-r384-xp75 Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit”
“Aliases: CVE-2026-33017, GHSA-vwmf-pq79-vjvx Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.