Skip to content
LangflowGHSA-g22f-v6f7-2hrh

Langflow affected by Remote Code Execution via validate_code() exec()

HighCVE-2026-0770 · Published Jan 23, 2026 · updated Jul 7, 2026

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.

GitHub advisory

Affected versions

PackageAffectedFixed in
langflow
PyPI
<= 1.7.3No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Severity from
GitHub (reviewed advisory)
Weakness
CWE-829
Also known as
CVE-2026-0770, PYSEC-2026-1525

More Langflow advisories

All Langflow
Advisory
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
Critical9.8Mar 17
Langflow has Remote Code Execution in CSV Agent
Critical9.8Feb 27
Langflow Missing Authentication on Critical API Endpoints
HighJan 2
External Control of File Name or Path in Langflow
High7.1Dec 19, 2025
Langflow vulnerable to Server-Side Request Forgery
High7.7Dec 19, 2025
Langflow CORS misconfiguration enables Account Takeover and RCE
Critical8.8Dec 6, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.