Vulnerability threat dossier

CVE-2026-0769

langflowlangflow

Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of eval_custom_component_code function. The issue results from the lack of proper validation of a user-supplied string before using it to execute python code. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-26972.

VTP deterministic threat24.6of 100 · CVSS excluded

VTP analyst assessment

Langflow unauthenticated eval injection

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityMEDIUM
AI confidence55%
Public exploitation · VTP factREPORTED

Assessment

Metadata describes CVE-2026-0769 as an unauthenticated Langflow eval_custom_component_code injection permitting remote arbitrary-code execution, with CVSS 9.8 and Langflow 1.3.2 listed. Exploitation is asserted, but the assertion's cited source summary names CVE-2026-0768, creating a material attribution uncertainty.

Why it matters

  • If the metadata attribution is correct, the flaw is network-accessible without authentication or user interaction and can fully compromise an affected instance.
  • EPSS is 0.37963, which is predictive context and does not prove exploitation.

Evidence

3 record references and 3 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The evidence attached to the exploitation assertion explicitly references CVE-2026-0768 rather than CVE-2026-0769; the second press summary is truncated before identifying the CVEs.

Neither press source has established independence, no KEV entry is supplied, and VTP observation is unknown.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Validate whether exploitation reporting and fixes apply to CVE-2026-0769 or the separately named CVE-2026-0768.

AI baseline history (2)
  1. BASELINE ASSESSED
    Langflow unauthenticated eval injectiongpt-5.6-sol · high
  2. BASELINE ASSESSED
    Unresolved CVE with disputed exploitation contextgpt-5.6-sol · high
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.4199th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.41; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

0 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:8f7454a1232a1630e59d9a8592cd02a1dbe579cfc6dabaa971ecb157233852afACTIVE
Evidence
04

Event history

Threat timeline

  1. 12:0701 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    SecurityWeek supplied a deterministically extracted signal; review the linked evidence before escalation.

05

Original publications

Source record

Hackers Start Exploiting Critical Langflow Vulnerability

Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely. The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek .

CVE-2025-3248CVE-2026-0768CVE-2026-0769CVE-2026-5027
Separate evidence group
Original

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka

CVE-2025-3248CVE-2026-0768CVE-2026-0769CVE-2026-5027CVE-2026-66066
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score24.6vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction8.15 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-95
CPE records
1
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.