Knox CVE Database
/
CVE-2026-0770
Critical
9.8

CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

Added to the CISA KEV catalog:
July 21, 2026

Overview

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.

Vulnerability details

Affected vendor
Langflow
Affected product
Langflow
Weakness type (CWE)
CWE-829

Langflow's validate endpoint accepts an exec_globals parameter and passes it into a dynamic execution context without adequate restriction. This is a CWE-829 (Inclusion of Functionality from Untrusted Control Sphere) weakness: the application treats attacker-supplied input as a trusted resource and executes it rather than treating it as data. Because the parameter is consumed by what is effectively a server-side code execution primitive, the trust boundary between user input and executable code is absent, giving the attacker direct control over the server's execution environment.

An attacker sends a crafted HTTP request to the Langflow validate endpoint containing a malicious exec_globals parameter value. No authentication is required, and the endpoint must only be network-reachable to be exploitable. The server processes the parameter through its dynamic execution context and runs the attacker-supplied code as root, yielding full system compromise: arbitrary file access, data exfiltration, process execution, and the ability to persist on or pivot from the host. The ZDI advisory was published as a zero-day with no vendor fix confirmed at time of disclosure.

Severity and impact

9.8
Critical
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor HTTP request logs for requests to the Langflow validate endpoint that include an exec_globals parameter, particularly from sources outside expected internal or developer IP ranges.
  • Alert on unexpected child processes or shell execution spawned from the Langflow application process, especially those running as root with no corresponding legitimate workflow trigger in application logs.
  • Audit for new files, cron entries, or network listeners created under the Langflow process owner (root) that do not correspond to a known deployment or configuration change event.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 24, 2026

Additional hardening

  • Place Langflow behind a network perimeter control (firewall, reverse proxy, or VPN gateway) so the validate endpoint is not directly reachable from untrusted networks.
  • Apply strict egress filtering on the Langflow host to limit outbound connections to known destinations, reducing the attacker's ability to exfiltrate data or fetch secondary payloads.
  • Run the Langflow process under a least-privilege service account rather than root; this does not prevent code execution but limits the blast radius of a successful exploit.
  • If the validate endpoint is not required for production operation, disable or block it at the application or proxy layer until a vendor-supplied fix is available.

Key dates

Published (NVD)
January 22, 2026
Added to CISA KEV
July 21, 2026
Remediation deadline
July 24, 2026
Last updated
July 22, 2026

References

Frequently asked questions

Does CVE-2026-0770 affect my FedRAMP authorization?

If Langflow Langflow runs inside your authorization boundary, yes. CVE-2026-0770 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, which carries a remediation deadline of July 24, 2026. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding — one you either remediate or formally document a mitigation for before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-0770?

Knox doesn't patch your software for you — remediating Langflow Langflow is your responsibility under the FedRAMP shared responsibility model. What Knox gives you is the pre-authorized, single-tenant boundary to remediate in, plus continuous compliance monitoring and audit-artifact coverage that help you document the fix for your next assessment. The fix is yours to apply; staying compliant while you apply it isn't something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's continuous monitoring, powered by KnoxAI, watches your environment in real time for newly disclosed vulnerabilities and compliance issues. Exposure surfaces as part of ongoing monitoring — not only when an assessor flags it at review time.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path — FedRAMP in 90 days for 90% less, without dependency or delay.

What happens if CVE-2026-0770 isn't remediated by July 24, 2026?

It becomes a POA&M item, and a growing POA&M list is what turns a routine continuous-monitoring review into a real conversation with your agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

What this vulnerability means for your FedRAMP compliance

Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, FedRAMP continuous monitoring puts a hard remediation clock on it. The clock starts on awareness — and missing the deadline can put an Authority to Operate at risk.

FedRAMP remediation deadlines for actively exploited vulnerabilities

FedRAMP ConMon SLAs give cloud providers 30, 90, or 180 days by severity — but KEV-listed flaws carry the tighter CISA deadline shown above. For authorized services, that date is the compliance line that assessors and agency sponsors will check.

How Knox reduces the burden of CVE vulnerabilities

Remediating the flaw is your responsibility under the FedRAMP shared responsibility model — but staying compliant while you fix it isn't something you manage alone. KnoxAI's continuous monitoring surfaces exposure in real time, and Knox keeps your continuous-monitoring evidence and audit artifacts current while you apply the fix. Learn more about the Knox platform.

How to limit your exposure through inherited controls and isolation

Knox's single-tenant architecture gives every customer a dedicated boundary, and 60–80% of FedRAMP controls are inherited from the platform — shrinking the surface you have to patch and prove. See why teams choose Knox.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting