← Back to Feed
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
CVE-2026-0770
July 31, 2026 · CISA · Severity: CRITICAL
Langflow Langflow: Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
Vendor: Langflow
Product: Langflow
CISA Date Added: 2026-07-21
CVE: CVE-2026-0770
This vulnerability is actively exploited in the wild according to CISA Known Exploited Vulnerabilities catalog.
Key Takeaways
- CVE-2026-0770 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
- This critical-severity vulnerability affects Langflow Inclusion of Functionality from Untrusted Control Sphere and could lead to system compromise.
- CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
- Langflow Langflow: Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.