CVE-2026-0770
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
Description
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.
Description as published by the source, in English.
Key facts
- Published
- 2026-01-23
- Last modified
- 2026-07-22
- Assigned by
- zdi-disclosures@trendmicro.com
- CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Scored by
- zdi-disclosures@trendmicro.com
- Probability of exploitation
-
56.3 %
higher than 99 %
of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15 - Fix available
- Not registered in the sources
Actively exploited
CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-07-21, with a remediation deadline of 2026-07-24 for US federal agencies.
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| langflow (PyPI) | ≤ 1.7.3 | Affected | |
| Langflow | Langflow | ≤ 1.7.3 | Affected |
Weakness type
-
CWE-829: Inclusion of Functionality from Untrusted Control Sphere
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
Attack techniques
Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK. This shows which techniques the weakness class is historically used for. It does not assert that this vulnerability has been exploited that way.
- T1055: Process Injection
- T1176: Software Extensions
- T1195.001: Compromise Software Dependencies and Development Tools
- T1505.004: IIS Components
- T1505.005: Terminal Services DLL
- T1574.006: Dynamic Linker Hijacking
- T1574.013: KernelCallbackTable
- T1620: Reflective Code Loading
References
- https://www.zerodayinitiative.com/advisories/ZDI-26-036/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-0770
Related at Berigo
Articles
-
Unit 42: Chinese speaking actor ran autonomous attacks with an AI agent
Same product
2026-07-31
On 30 July 2026 Unit 42 published a campaign in which a Chinese speaking actor let an AI agent find targets, fetch exploit code and attempt exploitat…
-
AI agent chose targets and switched vulnerability on its own in Chinese campaign
Same product
2026-07-31
Unit 42 describes a Chinese speaking actor who paired the DeepSeek language model with the Hermes Agent framework, and let the setup find targets, pu…
-
Sysdig documents the first observed case of agentic ransomware
Same product
2026-07-01
Sysdig reports on JADEPUFFER, an AI-driven extortion operation that automated the entire attack chain from entry to database encryption.
Does this affect you?
A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.