CVE-2026-0770
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
9.8
CVSS 3.0
63.8 %
EPSS (current)
2026-07-21
KEV addition
No
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Langflow / Langflow
Published: 2026-01-23 · Due (CISA): 2026-07-24
CWE: CWE-829 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | http/cves/2026/CVE-2026-0770.yaml | Langflow < 1.3.0 - Remote Code Execution via validate_code() exec() | – |
| metasploit | exploit/multi/http/langflow_rce_cve_2026_0770 | exploit/multi/http/langflow_rce_cve_2026_0770 | 2026-05-23 |
| exploitdb | 52597 | Langflow 1.3.0 - Remote Code Execution | 2026-05-29 |
References only — no downloads or instructions.