Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Critical Langflow Flaw Exploited to Steal OpenAI and AWS Keys

Threat actors are exploiting an unauthenticated remote code execution vulnerability, CVE-2026-0768, in Langflow, an open-source framework for building AI applications.

The critical flaw is located in Langflow’s code validator for custom components. It affects Langflow versions 1.4.2 and earlier and can allow arbitrary code execution with root privileges.

VulnCheck detected at least 50 exploitation attempts against its U.K. honeypots over the weekend. Attack traffic originated primarily from Russia, and VulnCheck lead security researcher Caitlin Condon said the number of observed attacks had risen to 360 as of today.

The attacks query environment variables and files to collect administrative credentials, superuser authentication keys, AWS secrets, and OpenAI API keys. Requests observed by VulnCheck queried LANGFLOW_SUPERUSER, OPENAI_API*, AWS_ACCESS*, and AWS_SECRET*, while also reading /root/.cache/langflow/secret_key and checking SSH access and the size of .bash_history.

Langflow is a Python-based low-code platform that lets users build AI applications, agents, chatbots, and retrieval-augmented generation systems through graphical workflows. Condon said there are no known public proof-of-concept exploits.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.