[KEV] CVE-2026-0770 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-0770 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-0770 is a remote code execution vulnerability in Langflow, caused by the inclusion of functionality from an untrusted control sphere.
Technical Detail
The flaw allows a remote attacker to cause an affected Langflow installation to include or execute functionality controlled outside the trusted application boundary. Successful exploitation can result in arbitrary code execution on the Langflow host, with the privileges of the Langflow service account. Authentication requirements, affected versions, and the precise exploitation path have not been confirmed in the available data.
Exploitation Status
Exploit maturity is assessed as Operational, indicating that exploitation capability is available and practical for use against affected environments. CISA has confirmed active exploitation in the wild. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on July 21, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize installation of Langflow security updates or vendor-provided fixes for this vulnerability. Under CISA Binding Operational Directive 22-01, federal civilian executive branch agencies must patch by August 11, 2026, or apply mitigations if patching is not possible. Until remediation is complete, restrict access to Langflow management and application interfaces to trusted users and networks, avoid exposing instances directly to the internet where possible, and limit the privileges available to the Langflow service account. Review Langflow, web server, and host logs for unexpected requests, newly created processes, suspicious command execution, or changes to application files and configuration. Specific detection indicators and complete workaround guidance have not been confirmed in the available data.