LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 21, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 24, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-0770 to its Known Exploited Vulnerabilities catalog on Jul 21, 2026, with a federal patch deadline of Jul 24, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

CVE-2026-0770 is an inclusion-of-functionality-from-untrusted-control-sphere weakness in Langflow that can let a remote attacker run arbitrary code on affected installations. For teams running Langflow in development, automation, or production workflows, successful abuse can mean full host compromise, so inventory and remediation should be treated as high priority until the vendor fix is confirmed and applied.

Public detail is limited to the CWE class and the CISA description of remote code execution; exact affected builds, attack preconditions, and scoring must be taken from the vendor advisory rather than assumed.

How it works

This issue is tracked as CWE-829: inclusion of functionality from an untrusted control sphere. In products of this class, the application loads or executes code, modules, or other functional components from a source the attacker can influence—such as a path, URL, package reference, or configuration value that is not adequately restricted to a trusted set.

When that control is missing or weak, a remote attacker who can supply or redirect that reference may cause the application to pull in and run attacker-chosen functionality in the context of the Langflow process. The CISA summary states that this can result in arbitrary code execution on affected installations. Specific request shapes, authentication requirements, and payload mechanics are not provided in the given facts and must be confirmed against the vendor advisory; defenders should assume a remote path to code execution until the advisory narrows the conditions.

Am I affected? How to find it in your systems

Langflow is typically deployed as a service or application stack used for building and running LLM/flow-based workloads—often on developer workstations, internal app servers, containers, or cloud instances that may be reachable from broader networks. Treat any host or cluster that runs Langflow as in scope until proven otherwise.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation for CVE-2026-0770 exactly as described in the Langflow advisory, and verify the installed version or build hash afterward. Align prioritization with CISA BOD 26-04 risk-based update guidance and any applicable forensics-triage expectations for your environment. For cloud-hosted or managed instances, follow the same BOD 26-04 cloud guidance or discontinue use if mitigations cannot be applied.

If you can't patch immediately

Reduce reachability and monitor aggressively until the vendor fix is in place.

If your data may have been exposed

Actively exploited remote-code-execution flaws are a common path into broader compromise and data theft, even when ransomware use is not documented for this CVE. If Langflow instances were exposed or you see signs of exploitation, follow your incident-response process: isolate affected hosts, preserve volatile evidence, rotate credentials and secrets that the service could access, and assess downstream systems the application could reach. As a quick personal check, you can run a free exposure scan of your email addresses against known breach datasets to see whether associated accounts appear in prior public dumps while you complete the full investigation.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedLangflow · Langflow
WeaknessCWE-829
Added to CISA KEVJul 21, 2026
Federal patch deadlineJul 24, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities