超危
Langflow exec_globals远程代码执行漏洞
2026-01-09 00:00:00 公开 ,2026-07-22 09:03:36 更新
- CISA KEV
- 关键漏洞
- 无需认证
- 远程
- 公开PoC
- 开源组件漏洞
- CWEs:
- CWE-829 (Inclusion of Functionality from Untrusted Control Sphere)
- CAPEC:
- CAPEC-175 (Code Inclusion) 、 CAPEC-201 (Serialized Data External Linking) 、 CAPEC-228 (DTD Injection) 、 CAPEC-251 (Local Code Inclusion) 、 CAPEC-252 (PHP Local File Inclusion) 、 CAPEC-253 (Remote Code Inclusion) 、 CAPEC-263 (Force Use of Corrupted Files) 、 CAPEC-538 (Open-Source Library Manipulation) 、 CAPEC-549 (Local Execution of Code) 、 CAPEC-640 (Inclusion of Code in Existing Process) 、 CAPEC-660 (Root/Jailbreak Detection Evasion via Hooking) 、 CAPEC-695 (Repo Jacking) 、 CAPEC-698 (Install Malicious Extension)
- SSVC:
- 可利用状态:已被积极利用攻击自动化:是技术影响评估:全部 2026-01-23 08:00:00