- Path traversal to RCE vulnerability in Langflow with CVSS 8.8
ThreatNoir Morning Brief — April 3
Morning Review in IT Security — April 3, 2026
The technology security landscape faces mounting pressure on multiple fronts as critical vulnerabilities emerge across artificial intelligence platforms, browser engines, PDF software, and open-source repositories. Organizations must prioritize patching efforts while remaining vigilant against active exploitation campaigns leveraging recent code leaks.
CVE-2026-5027: Langflow Path Traversal to Remote Code Execution
A critical vulnerability has been identified in Langflow with a CVSS score of 8.8, enabling attackers to execute remote code through path traversal exploitation. Source: ‼️ CVE-2026-5027: Langflow Path Traversal to Remote Code Execution PoC. The vulnerability affects AI-security infrastructure and open-source deployments, with proof-of-concept code already circulating publicly. Organizations utilizing Langflow in production environments should immediately assess their exposure and apply available patches to prevent unauthorized code execution.
CVE-2026-4698: JIT Miscompilation in Firefox's JavaScript Engine
Mozilla has disclosed a critical vulnerability in Firefox's Just-In-Time JavaScript compiler with a CVSS score of 8.8. Source: ‼️ CVE-2026-4698: JIT miscompilation in Firefox's JavaScript Engine. The vulnerability affects Firefox versions prior to 149, Firefox ESR versions below 115.34 and 140.9, and Thunderbird versions before 149 and 140.9. The flaw was discovered by security researcher maxpl0it and reported through Trend Micro's Zero Day Initiative. Users should upgrade to patched versions immediately to prevent potential code execution through malicious web content.
CVE-2026-3775: DLL Hijacking in Foxit PDF Editor/Reader Update Service
A DLL hijacking vulnerability has been discovered in the Foxit PDF Editor and Reader update service, creating a pathway for privilege escalation attacks. Source: CVE-2026-3775: DLL Hijacking in Foxit PDF Editor/Reader Update Service. This vulnerability allows attackers to execute arbitrary code with elevated privileges by placing malicious libraries in predictable locations where the update service searches for dependencies. Foxit users should verify they have the latest security updates installed and monitor their systems for suspicious update service behavior.
Claude Code Leak Exploited to Distribute Vidar Infostealer Malware
Threat actors are actively exploiting the recent Claude Code source code leak by creating fraudulent GitHub repositories designed to distribute Vidar information-stealing malware. Source: Claude Code leak used to push infostealer malware on GitHub. The campaign leverages the accidental disclosure of Claude Code source material to establish credibility for malicious repositories, with variants including ClaudeCode_x64.exe and GhostSocks payloads. Developers should exercise extreme caution when downloading code from GitHub repositories claiming to be related to Claude, verify project authenticity through official channels, and implement robust endpoint detection to identify Vidar infections.
Security teams should prioritize patching the identified CVE vulnerabilities while simultaneously strengthening their supply chain defenses against malware distribution campaigns. The convergence of critical zero-day vulnerabilities and active exploitation of leaked source code represents an elevated threat environment requiring immediate defensive action.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- JIT miscompilation vulnerability in Firefox JavaScript engine
- DLL hijacking vulnerability in Foxit PDF Editor/Reader update service, CVSS 7.8, local privilege escalation to SYSTEM
- VidarInformation-stealing malware deployed via fake Claude Code GitHub repositories
- GhostSocksNetwork traffic proxying tool deployed alongside Vidar infostealer
- ClaudeCode_x64.exeRust-based dropper executable distributing Vidar and GhostSocks