← signals
2026-07-22·LANGFLOW·security risk
meddown

Langflow, an open-source tool for building AI agents and workflows, has been flagged by CISA for a critical actively...

Langflow, an open-source tool for building AI agents and workflows, has been flagged by CISA for a critical actively exploited vulnerability (CVE-2026-0770) and added to the Known Exploited Vulnerabilities (KEV) catalog as of July 21, 2026, with a due date of July 24.

window 15devidence 23confidence score 100

confidence score

Strong evidence: 3 independent source classes support this read.

100
medium confidence3 independent source classesofficialotherpasses publish gate

signal brief

Langflow, an open-source tool for building AI agents and workflows, has been flagged by CISA for a critical actively exploited vulnerability (CVE-2026-0770) and added to the Known Exploited Vulnerabilities (KEV) catalog as of July 21, 2026, with a due date of July 24. This follows a flurry of other serious vulnerabilities disclosed in June and July 2026, including multiple remote code execution (RCE), IDOR, path traversal, and authentication bypass flaws (see OSV advisories PYSEC-2026-1521 through 1525, 221-224, 242-244, 376-379, 2565-2569). The cumulative disclosure signals that Langflow's codebase has systemic security weaknesses, especially around the Shareable Playground and public flow endpoints. The CISA KEV listing confirms active exploitation, which likely undermines enterprise trust and may slow adoption for production AI workflows. Organizations are required to patch by July 24 or discontinue use under BOD 26-04. The PyPI release of version 1.12.0.dev0 on July 22 suggests ongoing development, but the security posture remains a concern.

What the sources said:

  • CISA KEV: "Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations." (https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2026-0770)
  • OSV advisory PYSEC-2026-378: "Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit" (https://osv.dev/vulnerability/PYSEC-2026-378)
  • OSV advisory PYSEC-2026-243: "Langflow...contains a critical RCE vulnerability. Shareable Playground...execution of workflows by unauthenticated users." (https://osv.dev/vulnerability/PYSEC-2026-243)
  • OSV advisory PYSEC-2026-242: "Any authenticated user can read, modify, rename, or permanently delete another user's data by supplying the target's resource ID or flow_id." (https://osv.dev/vulnerability/PYSEC-2026-242)

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.