One request and the server is empty. Hackers have found a way to take OpenAI and AWS keys from AI bot creators

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
506
Reaction score
868
Deposit
0$
Servers for the development of AI applications have become repositories of valuable secrets available through one unprotected request. Attackers began exploiting the critical vulnerability of CVE-2026-0768 in Langflow to extract OpenAI and AWS keys, administrator credentials, and other sensitive information.

VulnCheck has discovered real attacks on baits in the UK. At first, the specialists registered more than 50 requests, and by September 1 the number of attempts increased to 360.

Langflow is an open platform in Python where developers collect AI agents, chatbots, and other applications in the graphics editor. Components link language models to databases, external APIs, and tools, so the server often stores access keys to cloud services and models.

The vulnerability of CVE-2026-0768 received a score of 9.8 out of 10 on the CVSS 3.1 scale and affects the user component verification handler. Langflow transmitted the resulting string to the Python interpreter without reliable filtering. You do not need an account and administrator actions to operate, and the implemented code is executed with the rights of the root superuser.

During attacks, attackers request LANGFLOW_SUPERUSER, OPENAI_API, AWS_ACCESS and AWS_SECRET environment variables. Additionally, queries read the Langflow internal secret key, check access to the SSH directory, and figure out the size of the Bash command history. Public demonstration exploit has not yet been found, but the absence of published code does not interfere with real exploitation.

The problem was revealed in January 2026, and the versions of Langflow 1.4.2 and below are considered vulnerable. Administrators are advised to switch to the current issue of 1.11.6 and restrict network access to the platform. When suspicious requests are detected, OpenAI, AWS and Langflow keys should be withdrawn and replaced, as well as check SSH access and command history on the server.
 
Top Bottom