Langflow AI Tool Under Attack: Critical Vulnerability Exploited
Summary
Attacks are surging against Langflow, an open-source tool for building AI agents. Attackers are exploiting a critical vulnerability that allows remote code execution without authentication. Cybersecurity firm VulnCheck warned that exploit attempts began on Saturday, targeting a flaw in Langflow's code validator. This vulnerability, tracked as CVE-2026-0768, has a critical CVSS score of 9.8. Attackers are performing reconnaissance and credential harvesting, querying environment variables and checking for sensitive access. Exploitation efforts remain active, with detections rising from 100 on Saturday to 360 by Monday. Traffic primarily originates from Russia and has hit systems in the U.K. Langflow is owned by IBM and integrated into its watsonx.ai platform. The vulnerability appears to be patched in version 1.10.1, released on June 23. This issue matters because it highlights ongoing security risks in popular AI development tools.
This is an AI-generated audio summary. Always check the original source for complete reporting.