news.mlab.sh
Back to the feed
vulnerability

Critical Langflow Flaw Exploited as Attacks on AI Platform Rise

CriticalCVSS 9.8
Summary

A critical remote code execution (RCE) vulnerability in Langflow, a low-code AI development platform, is being heavily exploited, leading to a significant increase in attacks targeting the platform. The vulnerability, initially disclosed in January, has seen a rapid expansion in attacker activity, originating from numerous countries and involving reconnaissance, credential harvesting, and even attempts to exfiltrate source code. The rise in attacks is linked to the growing adoption of AI technologies and Langflow's internet-accessible deployment model.

A critical Langflow vulnerability, CVE-2026-0768, is being actively exploited, marking a significant escalation in attacks against the low-code AI development platform. The vulnerability, initially reported by Trend Micro's Zero Day Initiative (ZDI) in January, allows for remote code execution (RCE).

VulnCheck researchers have observed sustained exploitation activity since Saturday, with the number of Canary detections increasing dramatically. As of Tuesday, the network has seen exploitation activity from approximately 20 different IPs across more than half a dozen countries. The attacks involve a mix of automated scanning, initial access attempts, and post-exploitation activities, including reading Langflow's secret_key, searching for API keys and cloud credentials, and attempting to locate SSH keys and .env files. Furthermore, some campaigns have involved Python scripts with Chinese-language comments, indicating an attempt to identify and exploit already-backdoored Langflow installations to establish persistence mechanisms.

Prior to this surge, only one Langflow flaw had been exploited in the wild. However, in 2026, things have changed rapidly, with 11 additional vulnerabilities now targeted and reported as exploited. This increase in activity is partly due to the widespread adoption of AI technologies, many of which lack robust security practices. Langflow’s internet-accessible deployment model also contributes to the problem, providing attackers with access to MCP servers, compute resources, and sensitive data within enterprise networks.

Langflow offers security best practices to reduce the attack surface, but these are often disregarded by users. Administrators should set non-default secret keys and consider additional controls to mitigate arbitrary code execution risk. The rapid escalation highlights the importance of minimizing exposure wherever possible.

Read the full article at Dark Reading