Hackers Exploit Critical Langflow and Ruby on Rails Flaws in Active RCE Attacks
Brief
Threat actors are actively exploiting two critical remote code execution vulnerabilities affecting Langflow and Ruby on Rails .
The campaigns target internet-exposed installations of the low-code AI application platform and the widely deployed web framework, underscoring how rapidly attackers are operationalizing newly disclosed flaws.
The first issue, CVE-2026-0768, is an unauthenticated remote code execution vulnerability in Langflow’s custom-component editor.
Critical Langflow and Ruby on Rails Flaws
The flaw lies in the code-validation path, where insufficient validation of a user-supplied parameter before it is used to execute Python can allow an attacker to run code in the context of the root user.
Caitlin Condon said its Canaries began recording first-time exploitation only hours earlier, despite no known public proof-of-concept exploit for the vulnerability.
