Critical Langflow flaw exploited to steal OpenAI and AWS keys

Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys.

The security issue received a critical severity rating and resides in the code validator of Langflow’s custom component editor.

Threat intelligence company VulnCheck detected the activity on its honeypots in the U.K. that were targeted in at least 50 exploitation attempts over the weekend, with attack traffic originating primarily from Russia.

VulnCheck lead security researcher Caitlin Condon said that the activity intensified and the total number of observed attacks increased to 360 as of today.

According to Condon, the attacker conducts reconnaissance and queries environment variables to harvest administrative credentials or superuser authentication keys for Langflow instances, AWS secrets, and OpenAI API keys.

“Among other things, attacker requests are querying environment variables (LANGFLOW_SUPERUSER, OPENAI_API*, AWS_ACCESS*, AWS_SECRET*), reading /root/.cache/langflow/secret_key, and checking .ssh access and .bash_history size,” Condon explained.

Langflow is an open-source, Python-based low-code platform for building AI applications, agents, chatbots, and retrieval-augmented generation (RAG) systems.

It lets users create workflows in a graphical interface by connecting components for language models, prompts, databases, APIs, and other tools.

The CVE-2026-0768 vulnerability was disclosed in January and affects Langflow versions 1.4.2 and earlier. It allows executing arbitrary code without authentication with root privileges.

“The specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code,” reads the vulnerability’s description.

Trend Micro’s Zero Day Initiative notes that it results from the lack of proper validation of a user-supplied string before using it to execute Python code.

Condon says that there are no known public proof-of-concept (PoC) exploits.

CVE-2026-0768 isn’t the first Langflow vulnerability that exploited this year. In March, attackers leveraged CVE-2026-33017, a critical code-injection flaw, within about a day of its disclosure, and used it to execute Python scripts and to harvest .ENV and database files.

This was followed by attacks exploiting CVE-2026-5027 to write arbitrary files to vulnerable servers and CVE-2026-55255 to access other users’ AI workflows, steal sensitive data, and deliver second-stage implants.

Attackers also exploited CVE-2026-0770 to execute commands with root privileges and attempted to deploy malware and extract cloud credentials, environment variables, and container metadata.

More recently, CISA warned that CVE-2026-9198 was being exploited after multiple proof-of-concept exploits became publicly available.

Langflow users are recommended to upgrade to the latest available version, 1.11.6, which addresses all known flaws in the popular tool.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

CISA orders urgent action on actively exploited Langflow RCE flaw

Critical Langflow RCE flaw exploited to hack AI app servers

Critical Avada WordPress theme flaw enables zero-click RCE

One threat actor responsible for 83% of recent Ivanti RCE attacks

CISA orders urgent patching of actively exploited Zimbra flaw

Massive Microsoft 365 outage causes auth issues, service failures

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Chrome Web Store extensions caught stealing crypto, browser data

AI-driven vulnerability discovery is accelerating. See how Action1 helps remediation keep pace.

Identity, Data Governance & Threat Detection in One Platform: Take our In-Browser Tour

Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.

Can you trust every session? See how session enrichment enables better authentication decisions.

Learn how ESET MDR can enhance your organization’s security posture

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.