important · Edge — Langflow
Attackers are using Langflow’s public validator to execute as root and probe cloud and API secrets.
Affects
Langflow, a self-hosted Python platform for building and deploying AI agents and workflows, commonly run in Linux containers.
An Internet-reachable validate endpoint executes unauthenticated Python supplied through its code parameter.
Detail and 6 sources
Observed payloads search environment variables and local files for Langflow administrator secrets, cloud credentials, API keys, SSH material, and shell history; no fixed release is known.
Sources
ResearchChecking your browser - reCAPTCHACode / PoCLangflow code Code Injection Remote Code Execution... · CVE-2026-0768 · GitHub Advisory Database · GitHubCode / PoCGitHub - langflow-ai/langflow: Langflow is a powerful tool for building and deploying AI-powered agents and workflows. · GitHubVendorCritical Langflow flaw exploited to steal OpenAI and AWS keysVendorZDI-26-034 - TrendAI™ Zero Day Initiative™ (ZDI)SecondaryNew exploits for DARKLANTERN, SPEAKINGSTONE, Windows Defender, Zimbra Collaboration, GeoServer, Flowise, Langflow, and more. - Initial Access