
⚡️ 0-Day Alert: IBM LangFlow OSS RCE LangFlow agent orchestration deployments have been under active exploitation since May. CVE-2025-34291: CORS misconfiguration + SameSite=None CVE-2026-33017*: Unauthenticated RCE via build_public_tmp's data parameter CVE-2026-55255: IDOR in /api/v1/responses: run any user's flow by ID CVE-2026-0770: Unauthenticated RCE via validate_code() / decorator abuse CVE-2026-9198: Unauthenticated RCE via auto_login + validate/code chain Bugs are not hard, likely spotted by generally available AI. Public exploit POCs exist. Majority takes input from an API endpoint variable and executes it directly on the OS. Attack pattern suggests that LangFlow has not seen basic security QA from the developer, and shouldn't be deployed in environments where arbitrary code execution poses a risk. * Attached: 33017 patch diff and code trace to exec()
Post summary
IBM’s open‑source LangFlow platform is being actively exploited in production, with multiple CVEs offering unauthenticated RCE and IDOR; public PoCs exist and a patch diff is available.
















