Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Self-Hosted AI & Data Tools Exploited: Langflow, LiteLLM, Metabase, Kestra, MLflow, Ray (2026)

Critical CVE-2026-9198, CVE-2026-0770, CVE-2026-55255, CVE-2026-42271, CVE-2026-59822, CVE-2026-72898, CVE-2026-49869, CVE-2026-64849, CVE-2025-62593, CVE-2026-48710 — CISA has added ten 2026 vulnerabilities in self-hosted AI, analytics and workflow platforms to its exploited list, most giving unauthenticated remote code execution. Fixed versions for Langflow, LiteLLM, Metabase, Kestra, MLflow, Ray and Starlette.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Tools that teams spin up quickly in Docker (Langflow, LiteLLM, Metabase, Kestra, MLflow, Ray) are being found on the internet and exploited, often with no login needed. Default Langflow installs hand out superuser tokens to anyone; Metabase's password-reset endpoint has a CVSS 10 SQL injection; Kestra's auth filter can be bypassed by ending a URL in /configs. Upgrade, and never expose these tools without authentication in front.

LangflowCVE-2026-9198 (auto-login + code validation → unauth RCE, through 1.10.0), CVE-2026-0770 (exec_globals RCE as root), CVE-2026-55255 (IDOR, < 1.9.1)
LiteLLMCVE-2026-42271 (MCP test endpoints run commands, 1.74.2–1.83.6), CVE-2026-59822 (MCP auth bypass, < 1.84.0)
MetabaseCVE-2026-72898: unauthenticated SQL injection via /reset_password → admin. CVSS 10
KestraCVE-2026-49869: suffix-match auth bypass → unauthenticated RCE. CVSS 10. Fixed 1.0.45 / 1.3.21
MLflow / Ray / StarletteCVE-2026-64849 (SSRF, 3.3.0–3.14.x), CVE-2025-62593 (browser DNS-rebinding RCE, < 2.52.0), CVE-2026-48710 (Host header path confusion, < 1.0.1)
Exploited?Yes, all ten on CISA KEV between June and September 2026

Why these keep getting hit

These platforms are usually deployed fast, from a docker run in a README, often on a cloud VM with a public IP, and many ship with authentication off or minimal by default. They also tend to hold API keys for paid services (OpenAI, Anthropic, cloud accounts) and database credentials. Attackers scan for them specifically, either to steal those keys or to mine crypto on the server.

Affected and fixed versions

ProductCVEWhat it isUpgrade to
LangflowCVE-2026-9198/api/v1/auto_login mints superuser tokens for any caller; chained with /api/v1/validate/code (runs code via exec()) = unauthenticated RCE on default installs. 1.0.0–1.10.0.Newer than 1.10.0 (see IBM advisory)
LangflowCVE-2026-0770exec_globals on the validate endpoint → unauthenticated code execution as root.1.9.0+
LangflowCVE-2026-55255IDOR on /api/v1/responses: run another user’s flow.1.9.1+
LiteLLMCVE-2026-42271MCP “test connection” endpoints accept a stdio command and run it (authenticated).1.83.7+
LiteLLMCVE-2026-59822Fake Authorization header triggers an OAuth2 fallback that skips key validation on the MCP endpoint.1.84.0+
MetabaseCVE-2026-72898SQL injection in /reset_password → admin, no login. CVSS 10.x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, x.63.5 or later
Kestra OSSCVE-2026-49869Auth filter allowlists any path ending in /configs → whole API without auth → RCE.1.0.45 / 1.3.21+
MLflowCVE-2026-64849Unauthenticated webhook test endpoint follows redirects → full-read SSRF (cloud metadata, internal services).3.15.0+
RayCVE-2025-62593Dashboard/API guarded only by a User-Agent check → a malicious web page in Firefox/Safari can run code on a developer’s Ray via DNS rebinding.2.52.0+
StarletteCVE-2026-48710Host header rebuilds request.url, so path-based security checks in middleware see a different path than the router. Affects any FastAPI/Starlette app relying on request.url.path for auth.1.0.1+

Am I affected?

# Which of these are running in Docker?
docker ps --format '{{.Image}}\t{{.Ports}}' | grep -iE 'langflow|litellm|metabase|kestra|mlflow|rayproject'

# Python environments
pip show langflow litellm mlflow ray starlette 2>/dev/null | grep -E '^(Name|Version)'

Metabase shows its version under Admin → Troubleshooting or at /api/session/properties (version.tag). Kestra shows it in the UI footer.

And the most important check: is it reachable from the internet? Look at the Ports column. Anything bound to 0.0.0.0 on a public host is exposed, regardless of firewall assumptions. Docker port publishing bypasses UFW by default.

How to patch

# Docker Compose: bump the tag (avoid :latest pins that never re-pull), then
docker compose pull && docker compose up -d

# pip installs
pip install -U langflow litellm mlflow ray starlette

For Starlette, update the framework in every FastAPI app you deploy and rebuild the images. It’s a library, so it’s inside your containers, not on the host.

Hardening

  • Bind to localhost or a private network (-p 127.0.0.1:7860:7860) and put an authenticating reverse proxy in front: Caddy with forward_auth to Authelia/Authentik, or a VPN. See our Caddy reverse proxy guide.
  • Langflow: set LANGFLOW_AUTO_LOGIN=false and configure a superuser. Auto-login is what makes CVE-2026-9198 unauthenticated.
  • LiteLLM: set a strong LITELLM_MASTER_KEY and keep the admin UI off the internet.
  • Ray: never expose the dashboard (port 8265) or GCS port; Ray has no built-in auth.
  • Rotate API keys stored in any of these tools if they were exposed on a vulnerable version. Stolen LLM keys get resold and run up huge bills.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories