
CVE-2026-27966
Pre-auth RCE scanner for Langflow < 1.8.0 — Route Injection + Vertex Injection → Code Execution (CVSS 9.8)
ai-securitycommand-and-controlexploitation+5
2

Pre-auth RCE scanner for Langflow < 1.8.0 — Route Injection + Vertex Injection → Code Execution (CVSS 9.8)

Just-in-time API keys for AI agents - and any other process you route through it: the caller only ever sees a placeholder.