CVE-2026-0770: Untrusted Component Execution in Langflow Actively Exploited in the Wild
CVE-2026-0770 is a KEV-listed, actively exploited flaw in Langflow that lets attackers trigger execution of untrusted components. Our detection catches it via anomalous outbound connections, child process spawns, and untrusted calls to flow-execution endpoints.