CVE-2026-7687General

LOWCVSS 2.1 · LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was determined in langflow-ai langflow up to 1.8.4. Affected by this issue is the function CodeParser.parse_callable_details of the file src/lfx/src/lfx/custom/code_parser/code_parser.py of the component Full Builtins Module Handler. Executing a manipulation can lead to command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-05-03); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-05-03: 2Mentions · 2026-06-14: 2Mentions · 2026-06-15: 1Mentions · 2026-06-20: 1PoC Mentioned / Linked · 2026-06-20: 1Technical Details · 2026-05-03: 2Technical Details · 2026-06-14: 1Technical Details · 2026-06-20: 105-0306-1406-1506-20
Signal classification3 categories
General
350.0%
Disclosure
233.3%
Exploit
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-032
Disclosure1General1
2026-06-142
Disclosure1General1
2026-06-151
General1
2026-06-201
Exploit1
Full discourse6 posts
  • YogSotho@YogSoth0
    Exploit

    🚨 #Langflow Multi-CVE Exploit Kit 💡 **CVE-2026-7524 (Path Traversal) | CVE-2026-7700 (Lambda eval) | CVE-2026-7687 (CodeParser CMD Injection)** 🧬 **Multi-Vector RCE Exploitation Framework** 😈 **Exploitation Chain:** 1. Create tar.gz with payload file + symlink pointing to target path (e.g., `../../../../tmp/shell.jsp`) 2. Upload to any vulnerable endpoint (`/api/v1/upload/archive`, `/api/v1/docling/`, etc.) 3. Archive extraction follows symlink → writes webshell to web root 4. Access webshell for persistent RCE #exploit #0days #security #hacking #CVE #CVSS #Langflow #unleaked

    Post summary

    The tweet details a multi-vector exploitation chain for three CVE-2026 entries in Langflow, outlining a path traversal and command injection process to deploy a webshell and achieve remote code execution.

    218097516.0K
    1.8K followersView on X
  • YogSotho@YogSoth0
    General

    # Langflow Multi-CVE Exploit Kit **CVE-2026-7524 (Path Traversal) | CVE-2026-7700 (Lambda eval) | CVE-2026-7687 (CodeParse> **Military-Grade Multi-Vector RCE Exploitation Framework** #exploit #0days #CVE #CVSS #security #hacking https://t.co/hB4tr07PJW

    Post summary

    The tweet announces a multi‑CVE exploit kit but provides no concrete PoC, exploit code, or detailed technical information, leaving the claim largely unsubstantiated.

    10090366
    1.8K followersView on X
  • YogSotho@YogSoth0
    Disclosure

    New 0days multi-exploit kit: Langflow Multi-CVE Reconnaissance Scanner Targets: CVE-2026-7524 (Path Traversal), CVE-2026-7700 (Lambda eval), CVE-2026-7687 (CodeParser) Military-grade async scanner with vulnerability fingerprinting and exploitability scoring. Soon on gibliz 0days

    Post summary

    A new multi‑exploit kit, Langflow Multi‑CVE Reconnaissance Scanner, targets CVE‑2026‑7524, CVE‑2026‑7700, and CVE‑2026‑7687 with vulnerability fingerprinting and exploitability scoring, but no PoC, code, or patch information is provided.

    11031319
    1.8K followersView on X
  • YogSotho@YogSoth0
    General

    **langflow_multi_cve.zip** | CVE-2026-7524, CVE-2026-7700, CVE-2026-7687

    Post summary

    The content only lists three CVE identifiers in a file name, lacking additional context, technical specifics, or actionable information.

    00010138
    927 followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🤖 AI Platform Alert: Langflow-ai (up to 1.8.4) vulnerable to Command Injection (CVE-2026-7687) via the Full Builtins Module. Monitor CVE-2026-7681 in COCO Annotator for Auth Bypass. Source: https://vuldb.com/vuln/360857

    Post summary

    This post discloses a command‑injection flaw (CVE-2026-7687) in Langflow‑ai up to version 1.8.4, noting the affected module but providing no exploit code, patch information, or evidence of active exploitation.

    1000057
    1.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7687 Command Injection in Langflow AI Langflow Up to Version 1.... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7687 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A concise tweet referencing CVE‑2026‑7687, noting a command‑injection flaw in Langflow AI (v1+) with a link to details, but lacking any PoC, exploit code, patch, or active exploitation information.

    0000045
    4.0K followersView on X

Explore more