CVE
CVE-2026-5027
Langflow - Path Traversal Arbitrary File Write via upload_user_file
Exploitation IoCs 6
Domain canary
Filename .bash_history
Filename .sysd
Filename /root/.cache/langflow/secret_key
IP France
IP Israel
MITRE ATT&CK TTPs 9
T1003 T1021 T1059.001 T1059.003 T1071.001 T1083 T1190 T1485 T1566
OS Credential Dumping
Credential Access
Remote Services
Lateral Movement
PowerShell
Execution
Windows Command Shell
Execution
Web Protocols
Command And Control
File and Directory Discovery
Discovery
Exploit Public-Facing Application
Initial Access
Data Destruction
Impact
Phishing
Initial Access
Source Articles
Critical Langflow flaw exploited to steal OpenAI and AWS keys
Threat actors are actively exploiting a critical unauthenticated remote code execution vulnerability, CVE-2026-0768, in Langflow, an open-source AI application framework, to steal sensitive credentials including OpenAI and AWS API keys. The flaw exists in the code validator of Langflow's custom component editor, allowing arbitrary Python code execution with root privileges. Attack activity has been observed on honeypots, primarily originating from Russia, with over 360 exploitation attempts detected. Attackers query environment variables and sensitive files to harvest credentials and maintain persistence.
bleeping-computer Sep 1, 2026
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Threat actors are actively exploiting two critical vulnerabilities, CVE-2026-0768 in Langflow and CVE-2026-66066 (KindaRails2Shell) in Ruby on Rails, to conduct credential probing, remote code execution, and command-and-control activities. Exploitation of CVE-2026-66066 involves uploading a crafted image to read sensitive files, leak environment secrets, and achieve RCE, particularly when libvips is used for image processing. Attackers have targeted canary systems globally, with source traffic traced to Russia and a single IP in France, and C2 infrastructure in Israel. Additional post-exploitation activities include deploying credential harvesters, cryptominers, disabling auditd, and lateral movement.
hacker-news Sep 1, 2026