CVE-2026-0769 is a critical eval-injection vulnerability in Langflow's eval_custom_component_code function. The function inadequately validates a user-controlled string before executing it as Python code. A remote unauthenticated attacker can supply malicious Python code and cause its execution in the context of the Langflow process. The vulnerability is rated CVSS 9.8 and has been observed in active exploitation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This two-file repository consists of a README with invocation examples and a standalone Python proof of concept, poc.py, targeting a claimed unauthenticated Langflow 1.3.2 remote-code-execution issue (CVE-2026-0769). The script accepts a target URL and optional Bash command, then POSTs a JSON object containing a `code` field and empty `frontend_node` field to `/api/v1/custom_component`. Its default behavior injects a custom Langflow component whose module-level divide-by-zero expression is intended to prove that supplied Python executes on the target. The optional command branch is designed to invoke Bash via Python subprocess with shell=True, but it references `command` instead of the defined `cmd` parameter. Consequently, command execution cannot be reached without correcting the source. The repository is not framework-based and does not include persistence, callback infrastructure, credential theft, or a reverse-shell payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated remote code execution vulnerability in Langflow, referenced by a Metasploit exploit module path.
A Langflow vulnerability referenced as having been affected by more than 15,000 successful attacks; no technical details are provided.
The content identifies CVE-2026-0769 in connection with Langflow (langflowai/langflow), with versions 1.8.4 and 1.9.0 and the /api/v1/version endpoint referenced. It does not describe the vulnerability type, impact, or affected-version range.
A Langflow vulnerability identified as one of three known exploited flaws involved in more than 15,000 observed successful attacks. No technical details are provided.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.