Langflow's Built-In Testing Tool Has No Password and Attackers Are Using It Right Now

Three critical flaws in the popular AI workflow builder let attackers run any code they like on your server, as root, without logging in. CISA ordered federal agencies to patch by May 26. Attackers are not waiting.

ThreatVectr NewsdeskAI-assistedPublished · Editor: Lee Brown· 4 min read
Illustration: A glowing network of interconnected nodes and data pipelines rendered in deep blue and amber
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • CVE-2026-0768 (CVSS 9.8), a code-injection flaw requiring no login, was being actively exploited in Langflow installations as of August 29, 2026, with VulnCheck recording over 360 attempts on UK honeypots shortly after public disclosure.
  • CISA added CVE-2025-3248 to its known-exploited vulnerabilities list on May 5, 2025, giving federal agencies until May 26, 2025, to patch.
  • Two further critical flaws, CVE-2026-0768 and CVE-2026-0769, both carry a CVSS score of 9.8.
  • Attackers who break in immediately hunt for OpenAI API keys, AWS credentials, and SSH keys stored in environment files.
  • VulnCheck has logged over 15,000 exploitation attempts across three related Langflow flaws before CVE-2026-0768 was added to that count.

Langflow is a drag-and-drop tool that lets business teams build AI-powered workflows without heavy coding. Connect it to OpenAI, to AWS, to internal databases, and automate tasks across all of them. That convenience is why it spread fast. It's also why attackers are treating it as a credential warehouse.

On August 29, 2026, VulnCheck's threat intelligence team began recording continuous exploitation attempts against Langflow servers exposed to the internet. The bug doing the damage is CVE-2026-0768, a code-injection flaw that lets an outsider feed their own instructions into the software and have them run as if they were legitimate commands.

What does this flaw actually do?

It lets an attacker send a crafted request to a Langflow server and run any code they choose on that machine, with full administrator privileges, no password required. The flaw sits inside a developer testing feature called the validate endpoint, a built-in tool that checks a code snippet before adding it to a workflow. Whatever code arrives gets passed straight into Python's exec() with no checks on who sent it or what it contains.

Two companion flaws carry the same danger rating. CVE-2026-0769 (CVSS 9.8) targets a different internal function called eval_custom_component_code, which executes code submitted for custom workflow components with no authentication and no input filtering. The earlier CVE-2025-3248 (CVSS 9.8), affecting Langflow versions before 1.3.0 and published April 7, 2025, hits the same validate endpoint through a slightly different path.

CVE Published CVSS What it lets attackers do Patched version
CVE-2025-3248 2025-04-07 9.8 Run any code via validate endpoint, no login 1.3.0

Should anyone outside enterprise IT be worried?

Directly, no. Langflow is a developer tool, not a consumer app. The credentials it stores are a different matter.

Once inside, attackers follow a consistent script: search for hidden configuration files called .env files, pull out API keys (digital passcodes granting access to paid AI services), harvest cloud account credentials, and grab SSH keys, the digital certificates that let one server log into another automatically. Those items go straight to outside servers the criminals control.

An OpenAI API key stolen this way runs up charges on the legitimate account holder and can expose proprietary data. AWS credentials open cloud storage and computing resources. Neither becomes safe when the Langflow patch lands. They must be cancelled and replaced immediately, and that's the step security teams most often skip. VulnCheck's research flags OpenAI and AWS credentials as the primary targets of the observed campaign.

The broader pattern is hard to ignore. Before 2026, only one Langflow vulnerability had ever been exploited in the wild. This year that number has risen to twelve. We covered the same dynamic playing out with Check Point flaws in our September 28 report: a tool becomes valuable enough to attack, exploitation follows fast, and federal patch deadlines land days later. The AI tooling category grew faster than security scrutiny could follow, and attackers moved in once the installed base was large enough to be worth the effort.

Anyone running Langflow should patch above version 1.4.2 now, audit which instances are reachable from the internet without a password, and rotate every credential the tool has ever touched. Treat exposed instances as breached until proven otherwise.

© 2026 Threat Vectr