Langflow Product Security Update Advisory (CVE-2026-0770)

Langflow Product Security Update Advisory (CVE-2026-0770)

Overview

Inappropriate handling of the exec_globals parameter in Langflow’s validate endpoint could lead to remote code execution (a vulnerability that allows a threat actor to execute arbitrary code remotely).

Affected Systems

  • Langflow version 1.7.3 Or earlier.
  • The vulnerability identifier is CVE-2026-0770.

Impact

  • Remote code execution is possible.
  • The CVSSv3 score is 9.8.

Response Status

  • As of July 27, no Vulnerability Patch for this vulnerability has been released.

Mitigation Recommendations

  • In accordance with guidance from the vendor and ZDI, restrict access to ensure that Langflow is not exposed to external networks.
  • Configure firewalls and network security policies to allow access only to trusted users and systems through them.

References

  • The reference sites include information on ZDI-26-036 and the GitHub Advisory Database.