Knox CVE Database
/
CVE-2026-0770
Critical
9.8

CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

Added to the CISA KEV catalog:
July 21, 2026

Overview

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.

Vulnerability details

Affected vendor
Langflow
Affected product
Langflow
Weakness type (CWE)
CWE-829

CVE-2026-0770 is a CWE-829 (Inclusion of Functionality from Untrusted Control Sphere) vulnerability in Langflow's validate endpoint. The endpoint accepts an exec_globals parameter and incorporates attacker-supplied content into server-side execution without restriction or sanitization. CWE-829 describes a class of flaws where an application treats externally controlled input as trusted code or a trusted resource, then executes it. Because Langflow processes this parameter without authentication requirements, the attack surface is the entire network-accessible validate endpoint.


An attacker sends a crafted HTTP request to the Langflow validate endpoint containing a malicious exec_globals parameter value. The server processes this input and executes the attacker-controlled functionality in the context of root, yielding full system compromise. No credentials are required. The outcome is arbitrary remote code execution as root, giving the attacker complete confidentiality, integrity, and availability impact over the affected installation. The advisory was published as a 0-day with no vendor fix available at time of disclosure, and CISA added this vulnerability to the Known Exploited Vulnerabilities catalog.

Severity and impact

9.8
Critical
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor web server or application logs for POST requests to the validate endpoint containing an exec_globals parameter from sources outside expected internal or authorized client IP ranges. Any such request from an external or unrecognized source warrants immediate investigation.
  • Watch for unexpected process spawning from the Langflow application process, particularly child processes running as root that are not part of normal Langflow operation, such as shells, interpreters, or network utilities.
  • Audit for new files, cron entries, or scheduled tasks created under root-owned directories following any request to the validate endpoint, as post-exploitation persistence is a common follow-on to root-level code execution.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 24, 2026

Additional hardening

  • Place Langflow behind a network perimeter control (firewall or reverse proxy) that restricts access to the validate endpoint to authenticated, trusted internal clients only. Block all unauthenticated external access.
  • If Langflow cannot be patched or taken offline, disable or block the validate endpoint at the application or proxy layer until a vendor fix is available, per ZDI advisory guidance.
  • Run Langflow under a least-privilege service account rather than as root to limit the impact of exploitation. The vulnerability executes code as root, so privilege reduction directly constrains attacker reach.
  • Conduct forensic triage per CISA BOD 26-04 requirements on any internet-exposed Langflow instance, reviewing process history, file system changes, and network connections for indicators of prior compromise.

Key dates

Published (NVD)
January 22, 2026
Added to CISA KEV
July 21, 2026
Remediation deadline
July 24, 2026
Last updated
July 22, 2026

References

Frequently asked questions

Does CVE-2026-0770 affect my FedRAMP authorization?

If Langflow runs inside your authorization boundary, CVE-2026-0770 is your problem. CISA's Known Exploited Vulnerabilities catalog lists this vulnerability with a remediation deadline of July 24, 2026. For a FedRAMP-authorized service, an unpatched Known Exploited Vulnerability inside the boundary is a finding your assessor and sponsoring agency will raise. You remediate it, formally document a mitigation for it, or both.

How does Knox help me handle CVE-2026-0770?

Remediating Langflow is your responsibility under the FedRAMP shared-responsibility model. Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work is yours to execute; maintaining a defensible compliance posture while you do it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. When something like CVE-2026-0770 surfaces, exposure registers during ongoing monitoring rather than waiting until an assessor flags it at review. That gap between disclosure and discovery closes considerably.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-0770 isn't remediated by July 24, 2026?

If you miss the July 24, 2026 deadline, CVE-2026-0770 becomes a Plan of Action and Milestones (POA&M) item, and every unresolved POA&M item adds weight to your next continuous-monitoring review. As that list grows, what should be a routine check-in with your sponsoring agency turns into a difficult conversation about overdue remediation. Hitting the deadline avoids that trajectory entirely, keeping your authorization clean and your agency relationship on solid ground.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting