01:09
2026-09-09
byteiota.com
ai-safety
Langflow CVE-2026-0768: Attackers Are Stealing Your AI API Keys Right Now
Attackers are actively exploiting CVE-2026-0768, a CVSS 9.8 unauthenticated remote code execution vulnerability in Langflow's `/api/v1/validate/code` endpoint, to steal OpenAI, AWS, Anthropic, and GCP…