Langflow Product Security Update Advisory (CVE-2026-0770)
Overview
Inappropriate handling of the exec_globals parameter in Langflow’s validate endpoint could lead to remote code execution (a vulnerability that allows a threat actor to execute arbitrary code remotely).
Affected Systems
- Langflow version 1.7.3 Or earlier.
- The vulnerability identifier is CVE-2026-0770.
Impact
- Remote code execution is possible.
- The CVSSv3 score is 9.8.
Response Status
- As of July 27, no Vulnerability Patch for this vulnerability has been released.
Mitigation Recommendations
- In accordance with guidance from the vendor and ZDI, restrict access to ensure that Langflow is not exposed to external networks.
- Configure firewalls and network security policies to allow access only to trusted users and systems through them.
References
- The reference sites include information on ZDI-26-036 and the GitHub Advisory Database.