CVE Details

CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Published: 2026-07-21 CVSS: 9.8 CRITICAL Product: Langflow Langflow Due Date: 2026-07-24

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.
  • affix/CVE-2026-0770-PoC • ⭐ 5 • 2026-02-07 • Conf: 96.0%
  • Proof of Concept for CVE-2026-0770 - Langflow Remote Code Execution

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 9.8
  • Severity: CRITICAL
  • Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

SSVC

  • Exploitation: active
  • Automatable: yes
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
dataType CVE_RECORD
dataVersion 5.2
cveMetadata > cveId CVE-2026-0770
cveMetadata > assignerOrgId 99f1926a-a320-47d8-bbb5-42feb611262e
cveMetadata > state PUBLISHED
cveMetadata > assignerShortName zdi
cveMetadata > dateReserved 2026-01-08T22:50:23.294Z
cveMetadata > datePublished 2026-01-23T03:28:52.286Z
cveMetadata > dateUpdated 2026-07-21T15:55:26.242Z
containers > cna > providerMetadata > orgId 99f1926a-a320-47d8-bbb5-42feb611262e
containers > cna > providerMetadata > shortName zdi
containers > cna > providerMetadata > dateUpdated 2026-01-23T03:28:52.286Z
containers > cna > title Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.
containers > cna > affected > 0 > vendor Langflow
containers > cna > affected > 0 > product Langflow
containers > cna > affected > 0 > versions > 0 > version 1.4.2
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > defaultStatus unknown
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > cweId CWE-829
containers > cna > problemTypes > 0 > descriptions > 0 > description CWE-829: Inclusion of Functionality from Untrusted Control Sphere
containers > cna > problemTypes > 0 > descriptions > 0 > type CWE
containers > cna > references > 0 > url https://www.zerodayinitiative.com/advisories/ZDI-26-036/
containers > cna > references > 0 > name ZDI-26-036
containers > cna > references > 0 > tags > 0 x_research-advisory
containers > cna > dateAssigned 2026-01-08T22:50:23.321Z
containers > cna > datePublic 2026-01-09T16:38:08.818Z
containers > cna > source > lang en
containers > cna > source > value Peter Girnus (@gothburz), William Gamazo Sanchez, and Alfredo Oliveira of Trend Research
containers > cna > metrics > 0 > format CVSS
containers > cna > metrics > 0 > cvssV3_0 > version 3.0
containers > cna > metrics > 0 > cvssV3_0 > vectorString CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
containers > cna > metrics > 0 > cvssV3_0 > baseScore 9.8
containers > cna > metrics > 0 > cvssV3_0 > baseSeverity CRITICAL
containers > adp > 0 > metrics > 0 > other > type ssvc
containers > adp > 0 > metrics > 0 > other > content > id CVE-2026-0770
containers > adp > 0 > metrics > 0 > other > content > role CISA Coordinator
containers > adp > 0 > metrics > 0 > other > content > options > 0 > Exploitation active
containers > adp > 0 > metrics > 0 > other > content > options > 1 > Automatable yes
containers > adp > 0 > metrics > 0 > other > content > options > 2 > Technical Impact total
containers > adp > 0 > metrics > 0 > other > content > version 2.0.3
containers > adp > 0 > metrics > 0 > other > content > timestamp 2026-07-21T15:45:21.869284Z
containers > adp > 0 > metrics > 1 > other > type kev
containers > adp > 0 > metrics > 1 > other > content > dateAdded 2026-07-21
containers > adp > 0 > metrics > 1 > other > content > reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0770
containers > adp > 0 > references > 0 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0770
containers > adp > 0 > references > 0 > tags > 0 government-resource
containers > adp > 0 > title CISA ADP Vulnrichment
containers > adp > 0 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 0 > providerMetadata > shortName CISA-ADP
containers > adp > 0 > providerMetadata > dateUpdated 2026-07-21T15:55:26.242Z