Langflow CVE-2026-0768 has been harvesting OpenAI and AWS keys since August
Key takeaways
- CVE-2026-0768 is an unauthenticated remote code execution bug in Langflow's custom component validate endpoint, scored 9.8 CVSS, and the code runs as root.
- VulnCheck observed continuous exploitation from around 29 August, from roughly 20 source IPs across more than six countries.
- Observed payloads pull Langflow admin environment variables, OpenAI API keys and AWS credentials, then move laterally and attempt persistence.
- Researchers count 11 further vulnerabilities being targeted on the same product, with over 15,000 successful exploitation attempts across the cluster.
A box that says test your code here has been running that code as root since at least 29 August. That is Langflow CVE-2026-0768, an unauthenticated remote code execution flaw in the open source visual builder for AI agent workflows, scored 9.8 on CVSS and under continuous exploitation for close to a month.
What the flaw actually is
The bug sits in Langflow's custom component editor. The validate endpoint exists so you can check a code snippet before adding it to a flow, and it passes the code parameter straight into Python's exec() without proper validation. No authentication is required to reach it. The process runs as root, so whatever arrives runs as root too.
This is not an exotic memory corruption bug that takes a specialist to weaponise. It is a text field that executes what you type, reachable by anyone who can see the port. That is why exploitation started quickly and has not stopped.
What attackers are taking
VulnCheck tracked continuous exploitation from roughly 29 August, coming from about 20 source IPs spread across more than six countries. The observed commands are not subtle. Attackers dump environment variables tied to the Langflow admin account, pull OpenAI API keys and AWS credentials out of them, then move laterally and try to establish persistence.
Credentials are the point. A stolen API key is money, and a stolen AWS credential is money plus everything that account can reach. The pattern matches what happened when unauthorised Gemini access hit three companies, where the AI layer was the door rather than the target.
Twelve CVEs on one product
Researchers have identified 11 further vulnerabilities being targeted on Langflow alongside this one, with over 15,000 successful exploitation attempts counted across the cluster. Twelve exploited CVEs on a single product says something about how fast the AI tooling sector shipped relative to how fast it hardened.
The thing being attacked is worth thinking about. Langflow is not a database holding one company's records. It is the layer people use to wire AI agents into everything else they own, which means it sits on top of a pile of credentials by design. Anything that orchestrates agents concentrates secrets in one place, and that place is now a known target. The same logic applies to edge devices with unauthenticated endpoints, which have been getting the same treatment for years.
What to do if you run it
Check whether any Langflow instance you own is reachable from the internet, and take it off the public internet if it is. Update to the patched release. Then treat every credential that instance could see as compromised: rotate the Langflow admin secrets, the OpenAI keys, the AWS access keys and anything else stored in its environment.
Check logs from 29 August onward for requests to the validate endpoint, and for outbound connections from the Langflow host to addresses you do not recognise. A key that was stolen in early September is still a valid key today unless someone rotated it, which is how breaches like the ShinyHunters PeopleSoft intrusion stayed useful long after the initial access.
The part worth sitting with is the timeline. Exploitation ran for nearly four weeks before most operators heard about it, which means the useful question is not whether you are patched now. It is what left the building before you were.