Known-exploited Langflow flaw allowed untrusted functionality to execute
OCCURREDJul 21, 2026
DOMAINAgentic Authority
EVIDENCE ASSURANCEA / Direct institutional record
SOURCEU.S. Cybersecurity and Infrastructure Security Agency
01 / EXECUTIVE SUMMARY
What the evidence establishes.
CISA added CVE-2026-0770 to the Known Exploited Vulnerabilities Catalog. The Langflow flaw includes functionality from an untrusted control sphere and can allow remote attackers to execute arbitrary code.
02 / WHAT HAPPENED
From accepted signal to real consequence.
CISA added CVE-2026-0770 to the Known Exploited Vulnerabilities Catalog. The Langflow flaw includes functionality from an untrusted control sphere and can allow remote attackers to execute arbitrary code.
03 / CLAIM-TO-CONSEQUENCE CHAIN
Four stages. One missing boundary.
The chain distinguishes what appeared valid, what was physically true, which authority followed and what consequence the source documents.
01 / DIGITAL CLAIM
What appeared valid.
An AI workflow component was accepted as part of a trusted execution environment.
02 / PHYSICAL REALITY
What was present.
Functionality supplied from an untrusted control sphere could obtain arbitrary code-execution authority.
03 / AUTHORITY & ACTION
What proceeded.
CISA directed agencies to apply vendor mitigations under BOD 26-04 or discontinue use when mitigations are unavailable.
04 / DOCUMENTED IMPACT
What the source records.
CISA classified the vulnerability as known exploited; the catalog does not quantify attributable loss.
MISSING TRUST BOUNDARY / 4SI ANALYSIS
A verifiable principal and origin boundary for every component allowed to execute inside an agentic workflow.
04 / ECONOMIC CONSEQUENCE RANGE
Evidence before false precision.
ECR separates a documented monetary floor from a modeled social and economic consequence envelope. It is not an accounting loss figure.
MODELED CONSEQUENCE RANGE
$990K–$30.6M
$5.50MCentral modeled position · USD equivalent
DOCUMENTED FLOOR$0
DATA COVERAGE60%
MODEL MODEproxy led
METHODECR 1.0
UNCERTAINTY
The public record establishes the control failure or authority action, not a realized loss total. The range is a deliberately wide scenario envelope.
05 / 4SI ANALYSIS
Source fact and inference remain separate.
Exploit status, product and required action come from the official CISA KEV record. 4SI supplies the Presence interpretation and score.
CONNECTION TO THE PRESENCE THESIS
Agentic workflow execution becomes unsafe when component origin is accepted without a current accountable principal.
ANALYTICAL LIMITATION
4SI does not claim to have independently verified the underlying event. Scores, boundary analysis and economic ranges interpret published evidence; they are not probabilities, compliance findings, valuations or loss forecasts.
06 / RELATED CASES
The same boundary, different context.
Related cases are editorially connected by domain, authority pattern or missing physical trust boundary.