A public proof-of-concept exploit has been released for CVE-2026-9198, a critical remote code execution flaw in Langflow OSS that affects versions 1.0.0 through 1.10.0 under default configurations exposing auto-login and code-validation endpoints. According to CSIRT Italia, attackers can chain two weaknesses to obtain SUPERUSER privileges and execute arbitrary code on vulnerable instances. The issue has been patched by the vendor, and organizations running exposed Langflow deployments have been urged to update immediately.
Additional reporting points to exploit-development and testing activity tied to Langflow, including references to artifacts such as langflowpoc.py and langflowtargets.txt, alongside infrastructure consistent with staging or proof-of-concept validation. While that material does not confirm victim compromise or attribute activity to a specific threat actor, it indicates that exploit code and targeting resources are circulating publicly, increasing the risk to internet-exposed Langflow systems, including deployments embedded in enterprise AI workflow environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A public proof-of-concept exploit was made available for CVE-2026-9198 in Langflow OSS. The disclosure highlighted exploitation conditions involving exposed auto-login and code-validation endpoints and advised users to update according to the vendor bulletin.
The vendor had already patched CVE-2026-9198, a critical remote code execution vulnerability affecting Langflow OSS versions 1.0.0 through 1.10.0 under default exposed settings. The issue could allow attackers to chain flaws to obtain SUPERUSER access and execute arbitrary code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.