On 2026-08-04, CISA added Langflow to its Known Exploited Vulnerabilities catalog for CVE-2026-9198, a code injection...
On 2026-08-04, CISA added Langflow to its Known Exploited Vulnerabilities catalog for CVE-2026-9198, a code injection vulnerability allowing unauthenticated full remote code execution on default deployments.
confidence score
Strong evidence: 3 independent source classes support this read.
signal brief
On 2026-08-04, CISA added Langflow to its Known Exploited Vulnerabilities catalog for CVE-2026-9198, a code injection vulnerability allowing unauthenticated full remote code execution on default deployments. This follows a wave of OSV advisories published throughout July 2026 covering multiple severe flaws: RCE via validate_code() (CVE-2026-0770), RCE (CVE-2024-48061), SSRF (CVE-2025-68477), missing authentication on critical API endpoints (CVE-2026-21445), path traversal in Knowledge Bases API (CVE-2026-42867), missing ownership check allowing authenticated users to read/modify/delete any flow (CVE-2026-34046), information leak via incomplete API key redaction (CVE-2026-6597), and cleartext storage of authentication settings (CVE-2026-6598).
What changed: Langflow is now on the CISA KEV list, triggering a mandatory remediation deadline of 2026-08-07 for federal agencies under BOD 26-04. Enterprises often follow suit with patch-or-discontinue policies, pressuring Langflow operators. The cumulative set of high-severity advisories suggests systemic security hardening gaps.
Affected stakeholders: Langflow users, enterprise AI teams evaluating the platform, and the broader AI dev-tool ecosystem. This creates immediate trust erosion and possible deployment pauses or migrations.
Direction: Down for Langflow. Active exploitation, a CISA deadline, and a cluster of critical vulnerabilities are a major negative signal for adoption and enterprise confidence.
What the sources said:
- CISA KEV: "Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments." (source)
- OSV advisory PYSEC-2026-1523: "Langflow vulnerable to remote code execution" (source)
- OSV advisory PYSEC-2026-1524: "Langflow Missing Authentication on Critical API Endpoints" (source)
- OSV advisory PYSEC-2026-2567: "Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check" (source)
source data used
“CVE: CVE-2026-9198 Vendor/project: IBM Product: Langflow Known ransomware campaign use: Unknown Due date: 2026-08-07 CWE: CWE-94 Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments....”
“A Python package with a built-in web application”
“Aliases: CVE-2024-9277, GHSA-355v-2rjx-fpx7 Inefficient Regular Expression Complexity in langflow”
“Aliases: CVE-2025-68477, GHSA-5993-7p27-66g5 Langflow vulnerable to Server-Side Request Forgery”
“Aliases: CVE-2024-48061, GHSA-5p5r-57fx-pmfr Langflow vulnerable to remote code execution”
“Aliases: CVE-2026-21445, GHSA-c5cp-vx83-jhqx, PYSEC-2026-2571 Langflow Missing Authentication on Critical API Endpoints”
“Aliases: CVE-2026-0770, GHSA-g22f-v6f7-2hrh Langflow affected by Remote Code Execution via validate_code() exec()”
Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.