AINewsnow

Your Langflow Instance Is Handing Attackers Root Access Right Now (CVE-2026-0768)

This story is from 2026-09-03. It is preserved in the archive; the latest stories are on the live feed.

The bug is embarrassingly simple Somewhere in Langflow's custom component editor is a /validate/code endpoint. You send it a string. It runs that string as Python. With root privileges. No auth required. That's it. That's the whole vulnerability. No fuzzing, no memory corruption, no chained exploit…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-03 09:02 · DEV Community — AI
    Your Langflow Instance Is Handing Attackers Root Access Right Now (CVE-2026-0768)

More stories

  1. Google Joins OpenAI, Anthropic, Meta in Disclosing AI Hacks — Bloomberg AI
  2. Alibaba ships Qwen3.8-Omni-Flash to watch, listen and call tools — r/LocalLLM
  3. Introducing Astra for Law — OpenAI News
  4. Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development — Politico Technology
  5. Sources: Anthropic considers releasing a new AI model to counter OpenAI's momentum since Astra's launch, ahead of an IPO and after Amodei's call for a slowdown (Reuters) — Techmeme
  6. Gemini Hacked Three Companies in First Known Breakout by Google’s AI — Wall Street Journal Technology
  7. OpenAI reveals cases of ‘concerning’ AI behaviour as it announces new disclosure system — The Guardian AI
  8. AI's role in building AI surging? Anthropic says Claude now leads 26% of its R&D — Mint AI

Get the daily brief of stories like this at 6:30 every morning →