Critical Langflow flaw used to steal OpenAI and AWS keys

Critical Langflow flaw used to steal OpenAI and AWS keys

Threat actors exploited an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open source framework for building AI applications, to steal credentials, tokens, and keys.

The security issue has been rated critical and is located in the code validator of Langflow’s custom component editor.

Threat intelligence company VulnCheck has discovered its UK honeypots were attacked in at least 50 exploitation attempts over the weekend, with attack traffic mostly coming from Russia.

VulnCheck lead security researcher Caitlin Condon said activity has picked up and the total number of observed attacks has increased to 360 to date.

According to Condon, the attacker performs reconnaissance and queries environment variables to gather administrative credentials or superuser authentication keys for Langflow instances, AWS secrets, and OpenAI API keys.

“Among other things, the attackers’ requests are environment variable requests (LANGFLOW_SUPERUSER, OPENAI_API*, AWS_ACCESS*, AWS_SECRET*), reading /root/.cache/langflow/secret_key, and checking .ssh access and the size of .bash_history,” Condon explained.

Langflow is open sourcea Python-based, low-code platform for building AI applications, agents, chatbots, and Retrieval Augmented Generative (RAG) systems.

It allows users to create workflows in a graphical interface by connecting components for language models, prompts, databases, APIs, and other tools.

The CVE-2026-0768 vulnerability was disclosed in January and affects Langflow versions 1.4.2 and earlier. Allows arbitrary code execution without root authentication.

“The specific vulnerability exists in the handling of the code parameter provided to the validation endpoint. The issue results from the failure to properly validate a user-supplied string before it is used to execute Python code,” it reads description of the vulnerability.

Trend Micro’s Zero Day Initiative notes that this is the result of not properly validating a user-supplied string before it is used to execute Python code.

Condon says there are no known public proof-of-concept (PoC) exploits.

CVE-2026-0768 is not the first Langflow vulnerability exploited this year. In March, attackers took advantage of CVE-2026-33017, a critical code injection vulnerability, within about a day of its disclosure and used it to execute Python scripts and harvest .ENV and database files.

This was followed by attacks using CVE-2026-5027 to write arbitrary files to vulnerable servers and CVE-2026-55255 to access other users’ AI workflows, steal sensitive data, and deliver second-stage implants.

Attackers also exploited CVE-2026-0770 to execute commands with root privileges and attempted to deploy malware and extract cloud credentials, environment variables, and container metadata.

Most recently, CISA warned that CVE-2026-9198 was being exploited after multiple proof-of-concept exploits became publicly available.

Langflow users are advised to upgrade to the latest version available, 1.11.6, which addresses all known flaws in the popular tool.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *