NPM · SEPTEMBER 2026 · EARLY WARNING

Langflow npm Package Under Attack: Critical Flaw Exploited

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
langflow (npm)
Affected versions
>= 1.4.2-NA, <= 1.4.2-NA or >= 1.4.2, <= 1.4.2
Patched version
Not yet available
CVE-2026-0768

An early warning has been issued regarding a critical vulnerability in the Langflow npm package which is reportedly being exploited in attacks targeting AI development platforms.

What happened

An early warning has been issued for a critical vulnerability in the Langflow npm package. This flaw is reportedly being exploited in attacks targeting AI development platforms. The specific versions affected are not specified in the available data. The exploit is currently active in the wild. Users of Langflow are advised to take immediate action to assess their exposure and consider alternatives until a fix is released.

The vulnerability is tracked under CVE-2026-0768. It was first flagged on 2026-09-01T20:48:52+00:00. The attack does not appear to be a supply-chain attack but a direct exploit of the Langflow package. The severity of this threat is high due to the critical nature of the vulnerability and its active exploitation.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If langflow is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using the Langflow npm package in your AI development projects you may be affected. The specific versions at risk are not detailed in the current data so it is advisable to assume vulnerability and take precautions.

What should I do right now?

Immediately monitor for updates on Langflow and consider using alternative AI development platforms. Review your dependencies and assess the potential impact of this vulnerability on your projects.

Has this been exploited in the wild?

Yes the vulnerability in Langflow is reportedly being exploited in active attacks.

Sources

Join the 0Day waitlist →

← Back to all threats