Critical Langflow flaw exploited to steal OpenAI and AWS keys
Summary
Threat actors are actively exploiting CVE-2026-0768, a critical unauthenticated remote code execution vulnerability (a flaw allowing attackers to run commands on a system without needing a password) in Langflow, an open-source platform for building AI applications. The attackers are stealing sensitive credentials like OpenAI API keys and AWS secrets by executing code through Langflow's custom component editor, with over 360 exploitation attempts detected in just one weekend.
Solution / Mitigation
Langflow users are recommended to upgrade to the latest available version, 1.11.6, which addresses all known flaws in the tool.
Classification
Affected Vendors
Related Issues
Original source: https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/
First tracked: September 1, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 95%