Langflow unauthenticated code-injection RCE added to CISA KEV (CVE-2026-9198)
Disclosed vulnerability17 Jul 2026A different CVE and class from the library's Langflow auth-bypass entry: an unauth RCE that reached CISA KEV under active exploitation. Because self-hosted AI-orchestration nodes hold LLM API keys, vector DBs and connected data, an actively-exploited default-config RCE turns AI-pipeline infrastructure into a widespread foothold. Figures are per NVD and CISA.
Risks it illustrates
Practise the risk class — related scenarios
Interactive simulations of the risk class this case illustrates (not a re-enactment of this specific event).
A coding agent asks to write ./notes.txt — the file it actually overwrites is your SSH keys
A text-to-SQL agent runs the model's output straight at the database
Compromise the pipeline that builds agents, and every new worker is born malicious
An auto-approving coding agent reads a poisoned page — and executes code it never should have
A fake Sentry error report hijacks a developer's coding agent into running a shell command
Every command is harmless on its own — the sequence is the exploit
A 'safe' dataset preview turns an upload into code execution on the pipeline's workers
A cost-saving open-weights swap quietly ships a model with its safety surgically removed
A capable third-party model that behaves perfectly — until it sees the trigger
A trusted MCP email tool quietly BCCs every message to an attacker