Illustration for: Hackers Are Actively Exploiting a Critical Langflow Flaw

Hackers Are Actively Exploiting a Critical Langflow Flaw

Attackers are actively exploiting a maximum-severity remote-code-execution flaw in Langflow, the open-source AI-agent framework, using it to harvest credentials and establish persistence rather than just crash servers.

By the Numbers

9.8 / 10
CVSS severity
CVE-2026-0768
CVE ID
January 2026
Disclosed
50+
Canary detections
12th for Langflow
Exploited CVE count
TC
By the AI Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
3 min read
ShareXLinkedInEmail

THE RUNDOWN

1

Attackers are actively exploiting an unauthenticated remote-code-execution flaw in Langflow, the open-source low-code platform widely used to build AI agents and RAG applications, with a maximum-severity 9.8 CVSS score.

2

Beyond running arbitrary code, attackers are reading Langflow's local secret-key file, probing SSH access, and checking bash history size -- reconnaissance aimed at credential theft and persistence, not just a crash.

3

It's Langflow's 12th exploited CVE, according to researchers, turning what started as a popular open-source AI-workflow tool into what one report calls credential-harvesting infrastructure.

4

Langflow was acquired by DataStax in 2024, which IBM is separately in the process of acquiring -- meaning IBM is inheriting security debt in a widely deployed AI tool as agentic AI adoption accelerates.

TC

The VC Read · Trace's Take

Trace Cohen

Twelve exploited CVEs in one open-source AI-agent framework is the number I'd put in front of every LP asking about agentic-AI infra exposure -- it's not a Langflow problem, it's a category problem, since n8n and Flowise sit on similarly thin security review budgets. The specific diligence question for any agent-tooling vendor now: show me your CVE-to-patch timeline, not your feature roadmap. IBM inheriting this via the DataStax deal is the sleeper risk nobody's pricing yet.

Analysis

Attackers are actively exploiting a critical, unauthenticated remote-code-execution vulnerability in Langflow, the open-source visual builder widely used to construct AI agents and retrieval-augmented-generation applications, The Hacker News reported. The flaw, tracked as CVE-2026-0768, carries a 9.8 out of 10 CVSS severity score and lives in the code validator inside Langflow's custom-component editor -- meaning an attacker needs no credentials to run arbitrary Python code on a vulnerable server.

The vulnerability was first disclosed in January 2026 by Trend Micro's Zero Day Initiative, but researchers say this is the first wave of confirmed real-world exploitation, with more than 50 detections logged on canary systems in the UK. The attack traffic has come primarily from Russia, and one campaign used Python scripts containing Chinese-language comments that appear to hunt specifically for Langflow instances already backdoored by other attackers -- suggesting multiple, unrelated threat actors are now racing to claim the same vulnerable population of servers.

Not Just a Crash -- Credential Harvesting Infrastructure

Beyond code execution, attackers observed in the campaign are reading Langflow's local secret-key file at a known filesystem path, checking SSH access configuration, and measuring the size of .bash_history files -- reconnaissance consistent with harvesting API keys, cloud credentials, and session tokens rather than simple defacement or crypto-mining. Researchers say this is Langflow's 12th exploited CVE, according to a separate report, and argue the pattern confirms popular AI-agent frameworks have effectively become credential-harvesting infrastructure for attackers targeting the broader AI supply chain -- a company's Langflow instance is now a target not because of what it does, but because of what secrets it touches.

Langflow, founded in 2020 by Rodrigo Nader and Gabriel Almeida as a self-funded consultancy before pivoting to the open-source Langflow tool, was acquired by DataStax in April 2024; DataStax itself is now being acquired by IBM, meaning IBM is inheriting a widely deployed AI tool with a growing exploited-CVE count at the exact moment enterprises are racing to deploy agentic AI. Langflow competes for the same low-code AI-workflow niche as n8n -- a more mature, business-automation-rooted platform with 2019 origins -- along with Flowise and a wave of newer agent-builder startups; Pulse has tracked the security gap opening up around agentic AI tooling before, as vendors race to ship agent capabilities faster than they can secure them.

For enterprise buyers and the VCs backing agentic-AI infrastructure startups, a 12th exploited CVE in one open-source framework is a genuine diligence red flag, not background noise -- security reviews of any AI-agent tooling vendor now need to specifically ask about code-execution surface area in custom-component or plugin systems, since that's exactly where Langflow's flaws keep recurring.

The counterweight is that Langflow's exposure is partly a function of its popularity and open-source distribution model, not unique recklessness -- widely deployed open tools accumulate CVEs simply because more researchers and attackers are looking at the code, and Trend Micro's own ZDI is the one that originally found and responsibly disclosed this bug back in January. The real failure here isn't Langflow shipping a flaw; it's the population of production deployments that still haven't patched an RCE disclosed eight months ago.

Any team running Langflow -- or evaluating an agent-builder vendor without a clear CVE-response track record -- should treat an unpatched eight-month-old 9.8-severity RCE as the baseline question to ask before the next one.

ShareXLinkedInEmail

Key Sources

2 sources

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.