we_are_coded.by CODE · The world, decoded
БГ
CISA KEV

A 9.8 hole in Langflow is under active exploitation: two open endpoints hand out full-access code execution

NVDSecurity

CVE-2026-9198 in Langflow - the visual builder for AI applications - lets anyone on the network issue themselves a SUPERUSER token and run arbitrary code, no password needed. On 4 August CISA added it to the catalog of actively exploited vulnerabilities. The patch is version 1.10.1.

In short
  • CVE-2026-9198: two unauthenticated API endpoints in Langflow hand out a SUPERUSER token and code execution - RCE with no password on a default install.
  • On 4 August CISA added the hole to the KEV catalog of actively exploited vulnerabilities; deadline for US federal agencies: 7 August.
  • Affected versions: 1.0.0 through 1.10.0. Fix: 1.10.1. Public installs - behind a VPN or authentication.
Checked on5 August 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Langflow is one of the tools people use to 'click together' AI agents with no code. Boxes, arrows, done. That's exactly why this hole hurts so much: there are a lot of installs, and their owners rarely follow security bulletins.

The facts: CVE-2026-9198 affects Langflow OSS from version 1.0.0 through 1.10.0 inclusive, scored 9.8 out of a maximum 10. The chain is two unauthenticated API endpoints: /api/v1/auto_login issues a SUPERUSER token, and /api/v1/validate/code executes submitted code - on a default install that means remote code execution with full privileges, no password at all. The vulnerability was published on 17 July, and on 4 August CISA added it to the KEV catalog of actively exploited vulnerabilities - the patch deadline for US federal agencies is 7 August, three days. The fix: version 1.10.1 or later. Sources: NVD and CISA KEV, 04.08.2026.

One thing I keep asking: how many of these installs even have an owner? Langflow gets spun up for an afternoon - a demo for the boss, an intern's experiment, a prototype to 'see if it works'. Then the demo keeps running on a server with a public address, and everyone forgets about it. Low-code AI builders became infrastructure without going through the discipline of infrastructure. Nobody puts 'patch every month' on their calendar for them.

And the second layer: these systems hold keys by definition. A Langflow install with no API keys to models and databases is a rarity, so a compromised install is not just another machine. It's a connection to everything the demo has ever touched.

The demo nobody remembers is the door everyone is looking for.

Check today: if you or a client is running Langflow, bump the version to 1.10.1 right away, and public access goes behind a VPN or at least proxy-level authentication. And one thing to remember for every AI demo from here on - either it has an owner and a patch calendar, or it gets switched off.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→NVD - CVE-2026-9198 (Langflow code injection), record as of 04.08.2026→CISA - Known Exploited Vulnerabilities Catalog
Original: https://wearecoded.com/en/articles/langflow-cve-2026-9198-kev.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news