← Back to Feed

Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

CVE-2026-0770

July 31, 2026 · CISA · Severity: CRITICAL

Langflow Langflow: Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. Vendor: Langflow Product: Langflow CISA Date Added: 2026-07-21 CVE: CVE-2026-0770 This vulnerability is actively exploited in the wild according to CISA Known Exploited Vulnerabilities catalog.

Key Takeaways

  • CVE-2026-0770 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
  • This critical-severity vulnerability affects Langflow Inclusion of Functionality from Untrusted Control Sphere and could lead to system compromise.
  • CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
  • Langflow Langflow: Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.
☕ Buy a Coffee