CVE-2026-0770: Langflow Inclusion of Functionality from Untrusted Control
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability. Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
- CISA KEV-listed (remediation due 2026-07-24)
- EPSS 10.4% (95.2% percentile)
- CVSS 9.8 critical