Critical Vulnerability in Langflow
24 July 2026
Attackers are exploiting a critical severity vulnerability in Langflow to execute arbitrary code. Users and administrators of affected products are advised to apply the latest security updates immediately.
Background
Security updates have been released to address a critical vulnerability (CVE-2026-0770) affecting Langflow. Langflow is an open source low-code tool for building Al agents and other Al applications. This vulnerability has a Common Vulnerability Scoring System (CVSS v3.1) score of 9.8 out of 10.
Impact
Successful exploitation of the remote code execution vulnerability could allow an unauthenticated attacker to remotely execute arbitrary code on affected installations of Langflow.
Known Exploitation
This vulnerability is reportedly under active exploitation.
Affected Products
This vulnerability affects Langflow versions 1.7.3 and earlier.
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
