{
  "entrypoint_kind": "endpoint",
  "entrypoint_detail": "POST /api/v1/validate/code (unauthenticated, LANGFLOW_AUTO_LOGIN=true)",
  "service_started": true,
  "healthcheck_passed": true,
  "target_path_reached": true,
  "runtime_stack": [
    "docker (overlay2)",
    "langflowai/langflow:1.1.1 (fastapi/uvicorn, digest-pinned)",
    "langflow validate_code() -> ast.parse + exec sink"
  ],
  "target_identity": {
    "repository_url": "docker.io/langflowai/langflow",
    "target_digest": "sha256:b56d4cfe18284e9fb2f1ec2d1bc9a29107a8c893397543e4937a55cda0136cd3",
    "runtime_digest": "sha256:b56d4cfe18284e9fb2f1ec2d1bc9a29107a8c893397543e4937a55cda0136cd3",
    "platform": "linux",
    "architecture": "x86_64"
  },
  "proof_artifacts": [
    "logs/repro/image_identity.txt",
    "logs/repro/containers.txt",
    "logs/repro/attempts/vuln_attempt_1_request.txt",
    "logs/repro/attempts/vuln_attempt_1_response.txt",
    "logs/repro/attempts/vuln_attempt_2_request.txt",
    "logs/repro/attempts/vuln_attempt_2_response.txt",
    "logs/repro/attempts/vuln_marker_a_request.txt",
    "logs/repro/attempts/vuln_marker_a_response.txt",
    "logs/repro/attempts/vuln_a_marker.txt",
    "logs/repro/attempts/vuln_marker_b_request.txt",
    "logs/repro/attempts/vuln_marker_b_response.txt",
    "logs/repro/attempts/vuln_b_marker.txt",
    "logs/repro/attempts/vuln_variant_decorator_request.txt",
    "logs/repro/attempts/vuln_variant_decorator_response.txt",
    "logs/repro/attempts/fixed_attempt_1_request.txt",
    "logs/repro/attempts/fixed_attempt_1_response.txt",
    "logs/repro/attempts/fixed_attempt_2_request.txt",
    "logs/repro/attempts/fixed_attempt_2_response.txt",
    "logs/repro/attempts/negative_control_observation.json",
    "logs/repro/attempts/fixed_auto_attempt_1_request.txt",
    "logs/repro/attempts/fixed_auto_attempt_1_response.txt"
  ],
  "artifact_sha256": {
    "logs/repro/image_identity.txt": "b36aad68f5fca3419d1ed6d7bb6fd2987ea77f1cb5bc2144ae7ee26d18c57677",
    "logs/repro/containers.txt": "b243a987bed5b8f03ed96e62358d7168086356b7252e9aa1f9376f2138c3faea",
    "logs/repro/attempts/vuln_attempt_1_request.txt": "96d26582c7279ec0d6c69b706dff0ae158ccb698cd10b07a044e2826e9f29fd6",
    "logs/repro/attempts/vuln_attempt_1_response.txt": "829d480a23d71776581df4d41f7c0ede85ac1cf9bcaaaed5b19ab63c64a6a696",
    "logs/repro/attempts/vuln_attempt_2_request.txt": "bf78c153d10c5e7a66055da19b9d9578398d8d4130970227d3dbf1a6731d076f",
    "logs/repro/attempts/vuln_attempt_2_response.txt": "829d480a23d71776581df4d41f7c0ede85ac1cf9bcaaaed5b19ab63c64a6a696",
    "logs/repro/attempts/vuln_marker_a_request.txt": "ae040407ef6850a8612d6118871c5895c7fe6e0b26a08222e518394b75cd8eab",
    "logs/repro/attempts/vuln_marker_a_response.txt": "829d480a23d71776581df4d41f7c0ede85ac1cf9bcaaaed5b19ab63c64a6a696",
    "logs/repro/attempts/vuln_a_marker.txt": "09e38e651d407d056b6084506eda4c8a19e9c4c02a07bc60addcfbb518280eff",
    "logs/repro/attempts/vuln_marker_b_request.txt": "2825a0abef89c170cccd8fb51b6a92a36e4248ca1506b82f5dd7237f3e185425",
    "logs/repro/attempts/vuln_marker_b_response.txt": "829d480a23d71776581df4d41f7c0ede85ac1cf9bcaaaed5b19ab63c64a6a696",
    "logs/repro/attempts/vuln_b_marker.txt": "7209a6611cc6d8c619a57b0d70bb76c37440fe0605c71a483fad61a37d7f32fb",
    "logs/repro/attempts/vuln_variant_decorator_request.txt": "5b790b46098c5e0b7bc61fbc4c20ae3a96c1037a8176f96afd8a16714edac5f0",
    "logs/repro/attempts/vuln_variant_decorator_response.txt": "186c16db4677dad05a596d2be9a046852484ac362e8e03cfb97adf4daea1cd7e",
    "logs/repro/attempts/fixed_attempt_1_request.txt": "29a0679e7e44344febb817055e74303230d1d09d62a9966573ab01bf61c382d1",
    "logs/repro/attempts/fixed_attempt_1_response.txt": "18acbd1a14b92ecabac4802a20390f55dc76860200d0853f85b7e20448a6509a",
    "logs/repro/attempts/fixed_attempt_2_request.txt": "ea332d3e5e4f1df16e870f7e89f4265961cf0ff965ebd594c54a46ccc7ac3bf3",
    "logs/repro/attempts/fixed_attempt_2_response.txt": "18acbd1a14b92ecabac4802a20390f55dc76860200d0853f85b7e20448a6509a",
    "logs/repro/attempts/negative_control_observation.json": "a0173b2c85e920467f00944c27539ecc1f013472cfa5a5f6816b5eea9f3357ab",
    "logs/repro/attempts/fixed_auto_attempt_1_request.txt": "933e765b4397c5ebc5f43c4ec6cbedd1ba911b18607e5f3d6ea241fe07e47735",
    "logs/repro/attempts/fixed_auto_attempt_1_response.txt": "829d480a23d71776581df4d41f7c0ede85ac1cf9bcaaaed5b19ab63c64a6a696"
  },
  "marker_values": {
    "vuln_instance_a": "PRUVA-CMDEXEC-1788272103-6040-A",
    "vuln_instance_b": "PRUVA-CMDEXEC-1788272103-6040-B",
    "negative_control": "PRUVA-CMDEXEC-1788272103-6040-C-NEGCTL"
  },
  "notes": "CVE-2026-0768 confirmed: unauthenticated POST /api/v1/validate/code on langflow 1.1.1 executes attacker Python (default-arg exec of FunctionDef) and exfiltrates command output in detail.function.errors[0]; marker files written inside two fresh vulnerable containers. Fixed control: langflow 1.3.0 with LANGFLOW_AUTO_LOGIN=false rejects with 401/403 and no marker; 1.3.0 default (auto-login) still executes (partial fix)."
}
