{"data":{"id":"1f363a93-bd17-42a5-a52d-4243da39e932","title":"The AI app builder your team trusts has a root-level backdoor","summary":"VulnCheck began observing continuous exploitation of CVE-2026-0768 (CVSS 9.8) against internet-facing Langflow instances on August 29, 2026. The flaw sits in the custom component editor's validate endpoint, which passes user-submitted code directly to Python's exec(), and in many default deployments requires no authentication, letting an attacker run arbitrary Python as root and harvest API keys, cloud and database credentials.","solution":"N/A -- no mitigation discussed in source.","labels":["security","industry"],"sourceUrl":"https://www.csoonline.com/article/4230802/the-ai-app-builder-your-team-trusts-has-a-root-level-backdoor.html","publishedAt":"2026-10-06T10:00:00.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"medium","attackType":["other"],"issueType":"news","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["Langflow"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-06T10:00:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}