Langflow CVE-2026-0768: unauthenticated code execution under active scan
Langflow validate endpoint remote code execution

Langflow CVE-2026-0768: unauthenticated code execution under active scan

F5 Labs published honeynet data on 6 October showing opportunistic scanning of CVE-2026-0768, an unauthenticated code-injection flaw in the Langflow AI application builder. Every one of 405 requests in September hit POST /api/v1/validate/code. The Zero Day Initiative rates it 9.8. The vulnerable handler evaluates attacker-supplied Python before authentication. If the service runs as root, that is root.

What happened

The bug was disclosed in January 2026 as ZDI-26-034. Exploitation did not stay theoretical. VulnCheck reported attempts from 29 August. F5's September sensors saw 55 source addresses, with bursts rather than a steady drip. The largest day was 26 September, about 40 percent of the month.

The payloads are not just probes. One cluster raises an exception carrying a unique marker, then uses a sleep to confirm execution. Another dumps the process environment with env, falling back to /proc/self/environ, which is where cloud keys and model API tokens usually sit. A third runs id through a default-argument trick. Some requests spoof localhost in forwarding headers. Others rotate User-Agent strings that look like AI crawlers.

Who is affected

  • Self-hosted Langflow reachable from the internet, especially builds up to and including 1.4.2, which ZDI lists as affected.
  • Any instance where /api/v1/validate/code answers without authentication in front of it.
  • Deployments that keep cloud credentials, model keys, or SSH material in the process environment.

What to do now

Take internet-facing Langflow off the public network, upgrade to a current release, and rotate every secret that process could read. A patch does not expire a key that was already dumped.

Search access logs for POST /api/v1/validate/code from outside the team, and for request bodies that call exec, env, or /proc/self/environ. If those lines exist, assume the cloud and AI keys on that host are burned. Langflow is a developer tool. It is now on the same scan list as mail servers and VPNs.

Source: F5 Labs, published 6 October 2026. https://www.f5.com/labs/articles/attackers-target-ai-development-platform-langflow

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Fake ChatGPT and Gemini ad portals steal Google and Okta MFA
Browser-in-the-browser phishing of advertising accounts