{"data":{"id":"b0dac87b-cb59-4c67-81de-c17d408953a6","title":"Critical Langflow flaw exploited to steal OpenAI and AWS keys","summary":"Threat actors are actively exploiting CVE-2026-0768, a critical unauthenticated remote code execution vulnerability (a flaw allowing attackers to run commands on a system without needing a password) in Langflow, an open-source platform for building AI applications. The attackers are stealing sensitive credentials like OpenAI API keys and AWS secrets by executing code through Langflow's custom component editor, with over 360 exploitation attempts detected in just one weekend.","solution":"Langflow users are recommended to upgrade to the latest available version, 1.11.6, which addresses all known flaws in the tool.","labels":["security"],"sourceUrl":"https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/","publishedAt":"2026-09-01T17:54:22.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":[],"issueType":"news","affectedPackages":null,"affectedVendors":["LangChain","OpenAI","Amazon"],"affectedVendorsRaw":["Langflow","OpenAI","AWS"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-01T17:54:22.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}