Threat actors are actively exploiting CVE-2026-0768 in Langflow to gain unauthenticated remote code execution and steal credentials, tokens, and keys from vulnerable AI application environments. VulnCheck observed escalating attacks against honeypots, with the attacker targeting environment variables and secret files to collect Langflow, AWS, and OpenAI credentials. #Langflow #CVE-2026-0768 #VulnCheck #OpenAI #AWS
Keypoints
- Attackers are exploiting CVE-2026-0768 in Langflow for unauthenticated remote code execution.
- The flaw affects Langflow 1.4.2 and earlier in the custom component editorβs code validator.
- VulnCheck recorded at least 360 exploitation attempts, mainly from Russia.
- Attackers are searching for LANGFLOW_SUPERUSER, AWS secrets, OpenAI API keys, and other sensitive data.
- Users are urged to upgrade to Langflow 1.11.6 to fix known vulnerabilities.