MediumNews
The AI app builder your team trusts has a root-level backdoor
- Published
- Record updated
Summary
VulnCheck began observing continuous exploitation of CVE-2026-0768 (CVSS 9.8) against internet-facing Langflow instances on August 29, 2026. The flaw sits in the custom component editor's validate endpoint, which passes user-submitted code directly to Python's exec(), and in many default deployments requires no authentication, letting an attacker run arbitrary Python as root and harvest API keys, cloud and database credentials.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database