CVE List

ZDI-26-037

Low

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Attack vectors and exploitability will vary depending on the configuration of the product. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2026-0771.

Published January 9, 2026.

Affected software

Get alerts for Langflow Langflow

Reference links