← advisory ledger

ADVISORY UNAUTH-2026-0044
TYPE cve
PRODUCT Langflow
SEVERITY CRITICAL

CRITICAL

Langflow CVE-2026-0770

published 2026-08-05 · updated 2026-08-05

Why it matters

Unauthenticated RCE via the exec_globals parameter of the validate endpoint (ZDI-26-036). Remote code execution as root, no login. Actively exploited (CISA KEV, added 2026-07-21). CVSS 9.8.

Affected versions

  • <=1.7.3

Fixed in: latest (advisory lists no fixed version; run the newest release)

Mapping provenance: human-verified against the linked advisory, last checked 2026-07-29. CISA KEV listed as actively exploited.

Fix it

Fix card: cve-2026-0770 →

References

Cite this record

unauth.dev advisory UNAUTH-2026-0044 — published 2026-08 · CC-BY 4.0

Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0044. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.