CVE-2026-9198 in Langflow - the visual builder for AI applications - lets anyone on the network issue themselves a SUPERUSER token and run arbitrary code, no password needed. On 4 August CISA added it to the catalog of actively exploited vulnerabilities. The patch is version 1.10.1.
- CVE-2026-9198: two unauthenticated API endpoints in Langflow hand out a SUPERUSER token and code execution - RCE with no password on a default install.
- On 4 August CISA added the hole to the KEV catalog of actively exploited vulnerabilities; deadline for US federal agencies: 7 August.
- Affected versions: 1.0.0 through 1.10.0. Fix: 1.10.1. Public installs - behind a VPN or authentication.
Langflow is one of the tools people use to 'click together' AI agents with no code. Boxes, arrows, done. That's exactly why this hole hurts so much: there are a lot of installs, and their owners rarely follow security bulletins.
One thing I keep asking: how many of these installs even have an owner? Langflow gets spun up for an afternoon - a demo for the boss, an intern's experiment, a prototype to 'see if it works'. Then the demo keeps running on a server with a public address, and everyone forgets about it. Low-code AI builders became infrastructure without going through the discipline of infrastructure. Nobody puts 'patch every month' on their calendar for them.
And the second layer: these systems hold keys by definition. A Langflow install with no API keys to models and databases is a rarity, so a compromised install is not just another machine. It's a connection to everything the demo has ever touched.
Check today: if you or a client is running Langflow, bump the version to 1.10.1 right away, and public access goes behind a VPN or at least proxy-level authentication. And one thing to remember for every AI demo from here on - either it has an owner and a patch calendar, or it gets switched off.