Description
Langflow versions up to and including 1.7.3 contain a remote code execution vulnerability in the `validate` endpoint where unsanitized values in `exec_globals`/`code` allow an attacker to execute arbitrary Python code. This module abuses the `/api/v1/auto_login` (or `/api/v1/login`) and `/api/v1/validate/code` endpoints to execute an arbitrary Metasploit command payload.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/multi/http/langflow/rce_cve_2026_0770msf undefined(rce_cve_2026_0770) > show actions ...actions...msf undefined(rce_cve_2026_0770) > set ACTION < action-name >msf undefined(rce_cve_2026_0770) > show options ...show and set options...msf undefined(rce_cve_2026_0770) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub