CVE-2026-7700Disclosure

LOWCVSS 2.1 · LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in langflow-ai langflow up to 1.10.2. This affects the function eval of the file src/lfx/src/lfx/components/llm_operations/lambda_filter.py of the component LambdaFilterComponent. Executing a manipulation can lead to code injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-05-03); latest day: 1
  • 8 total mentions across 5 days

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-05-03: 3Mentions · 2026-06-14: 2Mentions · 2026-06-15: 1Mentions · 2026-06-20: 1Mentions · 2026-10-06: 1PoC Mentioned / Linked · 2026-06-20: 1Exploit Tool / Code · 2026-06-14: 1Exploit Tool / Code · 2026-06-20: 1Technical Details · 2026-05-03: 3Technical Details · 2026-06-14: 1Technical Details · 2026-06-15: 1Technical Details · 2026-06-20: 105-0306-1406-1506-2010-06
Signal classification3 categories
Disclosure
342.9%
Exploit
342.9%
General
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-033
Disclosure3
2026-06-142
Exploit1General1
2026-06-151
Exploit1
2026-06-201
Exploit1
Full discourse8 posts
  • YogSotho@YogSoth0
    Exploit

    🚨 #Langflow Multi-CVE Exploit Kit 💡 **CVE-2026-7524 (Path Traversal) | CVE-2026-7700 (Lambda eval) | CVE-2026-7687 (CodeParser CMD Injection)** 🧬 **Multi-Vector RCE Exploitation Framework** 😈 **Exploitation Chain:** 1. Create tar.gz with payload file + symlink pointing to target path (e.g., `../../../../tmp/shell.jsp`) 2. Upload to any vulnerable endpoint (`/api/v1/upload/archive`, `/api/v1/docling/`, etc.) 3. Archive extraction follows symlink → writes webshell to web root 4. Access webshell for persistent RCE #exploit #0days #security #hacking #CVE #CVSS #Langflow #unleaked

    Post summary

    The tweet announces a Langflow multi‑CVE exploit kit, providing a concrete payload chain that can achieve RCE via path traversal, Lambda evaluation, and code‑parser injection, indicating a ready-to-use exploit framework.

    218097516.0K
    1.8K followersView on X
  • YogSotho@YogSoth0
    Exploit

    # Langflow Multi-CVE Exploit Kit **CVE-2026-7524 (Path Traversal) | CVE-2026-7700 (Lambda eval) | CVE-2026-7687 (CodeParse> **Military-Grade Multi-Vector RCE Exploitation Framework** #exploit #0days #CVE #CVSS #security #hacking https://t.co/hB4tr07PJW

    Post summary

    The tweet announces a military‑grade multi‑vector exploitation framework targeting CVE‑2026‑7524, CVE‑2026‑7700, and CVE‑2026‑7687, but lacks concrete code or patch details.

    10090366
    1.8K followersView on X
  • YogSotho@YogSoth0
    Exploit

    New 0days multi-exploit kit: Langflow Multi-CVE Reconnaissance Scanner Targets: CVE-2026-7524 (Path Traversal), CVE-2026-7700 (Lambda eval), CVE-2026-7687 (CodeParser) Military-grade async scanner with vulnerability fingerprinting and exploitability scoring. Soon on gibliz 0days

    Post summary

    The post announces a new multi‑exploit kit, Langflow, targeting several zero‑day CVEs with reconnaissance and scoring features, but it lacks explicit PoC details or patch information.

    11031319
    1.8K followersView on X
  • Ayyaz@ayyazdev

    Langflow's Smart Transform component asked an LLM to write a Python lambda, checked only that the reply started with "lambda" and contained a colon, then ran it through eval() with full builtins. That's CVE-2026-7700, rated 8.8 and published Oct 5. So lambda x: __import__("os").system("id") passed the check. A flow author could ask for it directly, and an exposed flow that feeds outside content into Smart Transform could get there through prompt injection. Langflow 1.10.3 and 1.11.0 now validate the generated code's AST and eval it with a restricted builtins map. If you can't upgrade yet, the advisory says to remove Smart Transform from runnable flows and keep untrusted data out of it. If anything in your app evals model output, treat it like code from whoever controls the prompt. Parse it against an allowlist and run it where it can't reach your credentials. https://github.com/advisories/GHSA-9fpm-3445-2vx4

    1003082
    84 followersView on X
  • YogSotho@YogSoth0
    General

    **langflow_multi_cve.zip** | CVE-2026-7524, CVE-2026-7700, CVE-2026-7687

    Post summary

    The brief excerpt merely lists a zip file name and three CVE identifiers, with no additional context on exploitation, mitigation, or technical details.

    00010138
    927 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7700 A weakness has been identified in langflow-ai langflow up to 1.8.4. This affects the function eval of the file src/lfx/src/lfx/components/llm_operations/lambda_filter.p… https://www.cve.org/CVERecord?id=CVE-2026-7700

    Post summary

    A CVE-2026-7700 weakness in the eval function of Langflow’s lambda_filter component has been reported, but no PoC, exploit, or patch details are provided.

    00001247
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7700 Code Injection in Langflow-AI Langflow Up to Version 1.8.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7700

    Post summary

    The entry reports a code injection vulnerability in Langflow‑AI up to version 1.8.4, with no PoC, exploit, or patch information provided.

    0000045
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7700 A weakness has been identified in langflow-ai langflow up to 1.8.4. This affects the function eval of the file src/lfx/src/lfx/components/llm_operations/lambda_filter.p… https://www.cve.org/CVERecord?id=CVE-2026-7700 ----- Traducción: CVE-2026-7700 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑7700 against langflow‑ai langflow up to version 1.8.4, noting a flaw in the eval function of a specific file, but provides no PoC, exploit, or patch details.

    0000034
    75 followersView on X

Explore more