CVE-2026-33017Active Exploitation(langflow / langflow)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 36 mentions and remains active

Immediate actions

  • Patch langflow langflow systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-08. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-94CWE-95CWE-306

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • langflow

Threat summary

  • Active exploitation appears in 257 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 340 mentions across 80 observed days

What's happening

  • Active exploitation reported across 257 signals
  • Exploit tool or code specified in 19 signals
  • PoC mentioned or linked in 42 signals
  • Patch or workaround mentioned in 87 signals
  • Technical details provided in 217 signals
  • Disclosure: 39 classified signals
  • General: 20 classified signals
  • Peaked 70d ago at 36 mentions (2026-03-27); latest day: 1
  • 340 total mentions across 80 days

Affected systems

Vendors
Products
langflow

Deep dive

Activity timeline340 mentions / 80d
09182736Mentions · 2026-03-18: 2Mentions · 2026-03-19: 6Mentions · 2026-03-20: 35Mentions · 2026-03-21: 15Mentions · 2026-03-22: 12Mentions · 2026-03-23: 15Mentions · 2026-03-24: 5Mentions · 2026-03-25: 21Mentions · 2026-03-26: 23Mentions · 2026-03-27: 36Mentions · 2026-03-28: 8Mentions · 2026-03-29: 14Mentions · 2026-03-30: 7Mentions · 2026-03-31: 10Mentions · 2026-04-01: 2Mentions · 2026-04-02: 4Mentions · 2026-04-03: 3Mentions · 2026-04-04: 1Mentions · 2026-04-06: 1Mentions · 2026-04-07: 2Mentions · 2026-04-08: 4Mentions · 2026-04-09: 1Mentions · 2026-04-10: 2Mentions · 2026-04-11: 2Mentions · 2026-04-13: 1Mentions · 2026-04-14: 1Mentions · 2026-04-18: 1Mentions · 2026-04-22: 1Mentions · 2026-04-30: 1Mentions · 2026-05-09: 2Mentions · 2026-05-10: 1Mentions · 2026-05-11: 1Mentions · 2026-05-13: 3Mentions · 2026-05-14: 4Mentions · 2026-05-15: 1Mentions · 2026-05-16: 1Mentions · 2026-05-17: 1Mentions · 2026-05-18: 2Mentions · 2026-05-19: 1Mentions · 2026-05-21: 1Mentions · 2026-06-10: 1Mentions · 2026-06-23: 4Mentions · 2026-06-24: 2Mentions · 2026-06-25: 1Mentions · 2026-06-26: 2Mentions · 2026-06-27: 5Mentions · 2026-06-28: 3Mentions · 2026-06-29: 2Mentions · 2026-06-30: 6Mentions · 2026-07-01: 6Mentions · 2026-07-02: 4Mentions · 2026-07-03: 4Mentions · 2026-07-04: 2Mentions · 2026-07-05: 2Mentions · 2026-07-06: 2Mentions · 2026-07-07: 1Mentions · 2026-07-08: 4Mentions · 2026-07-09: 1Mentions · 2026-07-10: 2Mentions · 2026-07-12: 3Mentions · 2026-07-15: 2Mentions · 2026-07-18: 1Mentions · 2026-07-19: 1Mentions · 2026-07-20: 1Mentions · 2026-07-22: 6Mentions · 2026-07-23: 2Mentions · 2026-08-01: 1Mentions · 2026-08-03: 1Mentions · 2026-08-04: 1Mentions · 2026-08-05: 1Mentions · 2026-08-07: 1Mentions · 2026-08-10: 1Mentions · 2026-08-13: 1Mentions · 2026-08-15: 1Mentions · 2026-08-20: 1Mentions · 2026-08-26: 2Mentions · 2026-08-29: 1Mentions · 2026-09-02: 1Mentions · 2026-09-15: 2Mentions · 2026-09-17: 1PoC Mentioned / Linked · 2026-03-20: 2PoC Mentioned / Linked · 2026-03-21: 3PoC Mentioned / Linked · 2026-03-22: 2PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-03-25: 1PoC Mentioned / Linked · 2026-03-27: 4PoC Mentioned / Linked · 2026-03-28: 3PoC Mentioned / Linked · 2026-03-29: 1PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-13: 1PoC Mentioned / Linked · 2026-05-10: 1PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-05-17: 1PoC Mentioned / Linked · 2026-05-19: 1PoC Mentioned / Linked · 2026-06-23: 2PoC Mentioned / Linked · 2026-06-28: 1PoC Mentioned / Linked · 2026-06-30: 2PoC Mentioned / Linked · 2026-07-01: 2PoC Mentioned / Linked · 2026-07-02: 2PoC Mentioned / Linked · 2026-07-05: 1PoC Mentioned / Linked · 2026-07-12: 1PoC Mentioned / Linked · 2026-07-23: 1PoC Mentioned / Linked · 2026-08-03: 1PoC Mentioned / Linked · 2026-08-13: 1PoC Mentioned / Linked · 2026-08-26: 1PoC Mentioned / Linked · 2026-09-02: 1PoC Mentioned / Linked · 2026-09-15: 1PoC Mentioned / Linked · 2026-09-17: 1Exploit Tool / Code · 2026-03-20: 2Exploit Tool / Code · 2026-03-21: 2Exploit Tool / Code · 2026-03-25: 1Exploit Tool / Code · 2026-03-27: 1Exploit Tool / Code · 2026-03-29: 1Exploit Tool / Code · 2026-05-10: 1Exploit Tool / Code · 2026-05-13: 1Exploit Tool / Code · 2026-05-16: 1Exploit Tool / Code · 2026-06-23: 2Exploit Tool / Code · 2026-06-25: 1Exploit Tool / Code · 2026-07-01: 2Exploit Tool / Code · 2026-07-12: 1Exploit Tool / Code · 2026-09-02: 1Exploit Tool / Code · 2026-09-15: 1Exploit Tool / Code · 2026-09-17: 1Active Exploitation · 2026-03-19: 2Active Exploitation · 2026-03-20: 30Active Exploitation · 2026-03-21: 13Active Exploitation · 2026-03-22: 10Active Exploitation · 2026-03-23: 12Active Exploitation · 2026-03-24: 4Active Exploitation · 2026-03-25: 11Active Exploitation · 2026-03-26: 20Active Exploitation · 2026-03-27: 28Active Exploitation · 2026-03-28: 3Active Exploitation · 2026-03-29: 11Active Exploitation · 2026-03-30: 6Active Exploitation · 2026-03-31: 5Active Exploitation · 2026-04-01: 2Active Exploitation · 2026-04-02: 4Active Exploitation · 2026-04-03: 3Active Exploitation · 2026-04-04: 1Active Exploitation · 2026-04-06: 1Active Exploitation · 2026-04-07: 2Active Exploitation · 2026-04-08: 3Active Exploitation · 2026-04-09: 1Active Exploitation · 2026-04-10: 1Active Exploitation · 2026-04-11: 2Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-04-14: 1Active Exploitation · 2026-04-18: 1Active Exploitation · 2026-04-22: 1Active Exploitation · 2026-05-09: 1Active Exploitation · 2026-05-10: 1Active Exploitation · 2026-05-11: 1Active Exploitation · 2026-05-13: 3Active Exploitation · 2026-05-14: 4Active Exploitation · 2026-05-15: 1Active Exploitation · 2026-05-16: 1Active Exploitation · 2026-05-17: 1Active Exploitation · 2026-05-18: 1Active Exploitation · 2026-05-19: 1Active Exploitation · 2026-05-21: 1Active Exploitation · 2026-06-10: 1Active Exploitation · 2026-06-23: 3Active Exploitation · 2026-06-24: 1Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-06-26: 2Active Exploitation · 2026-06-27: 4Active Exploitation · 2026-06-28: 2Active Exploitation · 2026-06-29: 2Active Exploitation · 2026-06-30: 4Active Exploitation · 2026-07-01: 4Active Exploitation · 2026-07-02: 3Active Exploitation · 2026-07-03: 3Active Exploitation · 2026-07-04: 2Active Exploitation · 2026-07-05: 1Active Exploitation · 2026-07-06: 2Active Exploitation · 2026-07-07: 1Active Exploitation · 2026-07-08: 3Active Exploitation · 2026-07-09: 1Active Exploitation · 2026-07-10: 1Active Exploitation · 2026-07-12: 3Active Exploitation · 2026-07-15: 2Active Exploitation · 2026-07-18: 1Active Exploitation · 2026-07-22: 5Active Exploitation · 2026-07-23: 2Active Exploitation · 2026-08-01: 1Active Exploitation · 2026-08-04: 1Active Exploitation · 2026-08-05: 1Active Exploitation · 2026-08-07: 1Active Exploitation · 2026-08-10: 1Active Exploitation · 2026-08-13: 1Active Exploitation · 2026-08-15: 1Active Exploitation · 2026-09-02: 1Patch / Workaround · 2026-03-18: 2Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-20: 4Patch / Workaround · 2026-03-21: 3Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-03-23: 4Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-03-25: 6Patch / Workaround · 2026-03-26: 9Patch / Workaround · 2026-03-27: 8Patch / Workaround · 2026-03-28: 2Patch / Workaround · 2026-03-29: 3Patch / Workaround · 2026-03-30: 3Patch / Workaround · 2026-03-31: 4Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-02: 2Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 4Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-11: 1Patch / Workaround · 2026-05-09: 1Patch / Workaround · 2026-05-10: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-27: 3Patch / Workaround · 2026-06-29: 2Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-01: 2Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-03: 1Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-07-08: 3Patch / Workaround · 2026-07-12: 1Patch / Workaround · 2026-07-18: 1Patch / Workaround · 2026-08-03: 1Patch / Workaround · 2026-08-07: 1Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-08-26: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-19: 4Technical Details · 2026-03-20: 13Technical Details · 2026-03-21: 9Technical Details · 2026-03-22: 8Technical Details · 2026-03-23: 7Technical Details · 2026-03-24: 2Technical Details · 2026-03-25: 18Technical Details · 2026-03-26: 15Technical Details · 2026-03-27: 25Technical Details · 2026-03-28: 7Technical Details · 2026-03-29: 10Technical Details · 2026-03-30: 5Technical Details · 2026-03-31: 5Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 4Technical Details · 2026-04-03: 3Technical Details · 2026-04-04: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-08: 4Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 2Technical Details · 2026-04-11: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-18: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-13: 2Technical Details · 2026-05-14: 2Technical Details · 2026-05-16: 1Technical Details · 2026-05-18: 2Technical Details · 2026-05-21: 1Technical Details · 2026-06-10: 1Technical Details · 2026-06-23: 2Technical Details · 2026-06-24: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-28: 2Technical Details · 2026-06-29: 2Technical Details · 2026-06-30: 6Technical Details · 2026-07-01: 5Technical Details · 2026-07-02: 4Technical Details · 2026-07-03: 3Technical Details · 2026-07-04: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-08: 3Technical Details · 2026-07-09: 1Technical Details · 2026-07-10: 1Technical Details · 2026-07-12: 1Technical Details · 2026-07-15: 1Technical Details · 2026-07-19: 1Technical Details · 2026-07-20: 1Technical Details · 2026-07-22: 4Technical Details · 2026-07-23: 2Technical Details · 2026-08-07: 1Technical Details · 2026-08-10: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-15: 1Technical Details · 2026-08-20: 1Technical Details · 2026-08-26: 1Technical Details · 2026-09-02: 1Technical Details · 2026-09-17: 103-1803-2604-0304-1305-1306-1006-3007-0807-2208-1309-17
Signal classification7 categories
Active Exploitation
24973.2%
Disclosure
3911.5%
General
205.9%
Patch
175.0%
PoC
102.9%
Exploit
41.2%
Referenced assets190 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-182
Patch2
2026-03-196
Active Exploitation2Disclosure4
2026-03-2035
Active Exploitation29Disclosure5Exploit1
2026-03-2115
Active Exploitation13PoC2
2026-03-2212
Active Exploitation10General2
2026-03-2315
Active Exploitation12Disclosure3
2026-03-245
Active Exploitation4Disclosure1
2026-03-2521
Active Exploitation10Disclosure4Exploit1General2Patch3PoC1
2026-03-2623
Active Exploitation20Disclosure3
2026-03-2736
Active Exploitation27Disclose1Disclosure1General3Patch3PoC1
2026-03-288
Active Exploitation3Disclosure2General1PoC2
2026-03-2914
Active Exploitation11Disclosure1General1Patch1
2026-03-307
Active Exploitation5Patch2
2026-03-3110
Active Exploitation4Disclosure3General1Patch2
2026-04-012
Active Exploitation2
2026-04-024
Active Exploitation4
2026-04-033
Active Exploitation3
2026-04-041
Active Exploitation1
2026-04-061
Active Exploitation1
2026-04-072
Active Exploitation2
2026-04-084
Active Exploitation2Patch2
2026-04-091
Active Exploitation1
2026-04-102
Active Exploitation1Disclosure1
2026-04-112
Active Exploitation2
2026-04-131
Active Exploitation1
2026-04-141
Active Exploitation1
2026-04-181
Active Exploitation1
2026-04-221
Active Exploitation1
2026-04-301
Disclosure1
2026-05-092
Active Exploitation1General1
2026-05-101
Active Exploitation1
2026-05-111
Active Exploitation1
2026-05-133
Active Exploitation3
2026-05-144
Active Exploitation4
2026-05-151
Active Exploitation1
2026-05-161
Active Exploitation1
2026-05-171
Active Exploitation1
2026-05-182
Active Exploitation1Disclosure1
2026-05-191
Active Exploitation1
2026-05-211
Active Exploitation1
2026-06-101
Active Exploitation1
2026-06-234
Active Exploitation3Disclosure1
2026-06-242
Active Exploitation1Disclosure1
2026-06-251
Active Exploitation1
2026-06-262
Active Exploitation2
2026-06-275
Active Exploitation4General1
2026-06-283
Active Exploitation2PoC1
2026-06-292
Active Exploitation2
2026-06-306
Active Exploitation4Disclosure1PoC1
2026-07-016
Active Exploitation4General2
2026-07-024
Active Exploitation3Disclosure1
2026-07-034
Active Exploitation3General1
2026-07-042
Active Exploitation2
2026-07-052
Active Exploitation1Disclosure1
2026-07-062
Active Exploitation2
2026-07-071
Active Exploitation1
2026-07-084
Active Exploitation2Disclosure1Patch1
2026-07-091
Active Exploitation1
2026-07-102
Active Exploitation1General1
2026-07-123
Active Exploitation2Exploit1
2026-07-152
Active Exploitation2
2026-07-181
Active Exploitation1
2026-07-191
Disclosure1
2026-07-201
General1
2026-07-226
Active Exploitation5Disclosure1
2026-07-232
Active Exploitation2
2026-08-011
Active Exploitation1
2026-08-031
PoC1
2026-08-041
Active Exploitation1
2026-08-051
Active Exploitation1
2026-08-071
Active Exploitation1
2026-08-101
Active Exploitation1
2026-08-131
Active Exploitation1
2026-08-151
Active Exploitation1
2026-08-201
Disclosure1
2026-08-262
General1Patch1
2026-08-291
General1
2026-09-021
Active Exploitation1
2026-09-152
Exploit1General1
2026-09-171
PoC1
Full discourse20 posts
  • Sans Limite@SansLimit3
    Active Exploitation

    Exposed attacker infrastructure combining #Hermes Agent, #CyberStrikeAI, #SliverC2, and multiple LLMs used for automated CVE targeting, exploit validation, Telegram-based orchestration, and post-exploitation validation workflows. Opendir: 142.171.160[.]137:8888 VULN-MONITOR: 142.171.149[.169:8001 - Real-time 1day/0day RCE tracking across 18 sources🤔 CyberStrikeAI Server: 100.81.245[.29:8080 Chain: FOFA/Shodan recon → AI-assisted target filtering → CVE/PoC enrichment → custom scanner & exploit generation → exploit validation → WebSocket/shell access → post-exploitation environment validation → Telegram-pushed operations. Targeted CVEs: CVE-2026-0300 (Palo Alto PAN-OS) CVE-2024-21762 (FortiOS/FortiProxy SSL-VPN) CVE-2026-33017 (Langflow) CVE-2026-21858 (n8n) CVE-2026-3055 (Citrix ADC/NetScaler) CVE-2026-34486 (Apache Tomcat) CVE-2026-25253 (OpenClaw/Moltbot/Clawdbot) @malwrhunterteam @500mk500 @1ZRR4H @MichalKoczwara

    Post summary

    The post highlights an automated attacker infrastructure using AI-driven targeting and real‑time validation of zero‑day RCE exploits across multiple CVEs, without sharing specific PoC or tooling details.

    837223619525.2K
    634 followersView on X
  • e_camli@ekinoks_26
    Active Exploitation

    Langflow just got hit with CVE-2026-33017. CVSS 9.3. Actively exploited to drop Monero miners on exposed endpoints. Same week: 282 iOS AI apps transmitting LLM API keys in cleartext. Anyone intercepting that traffic gets full backend access. Ade's response was two words: "Latch fixes this." He's right. But the more interesting signal came a day earlier. SCALE, Rialo's multi-agent coordination framework, is being integrated directly into Latch. That's a meaningful architectural expansion. Latch launched as access control for individual agents: what a single agent can touch, under what policy, on which machine. SCALE integration makes multi-agent coordination a first-class primitive inside that same framework. The difference matters. A single agent with bad access control is a security problem. A network of agents coordinating tasks with no verifiable handoff between them, no enforceable terms on delegated work, no accountability for what each agent did or didn't complete, is a systemic problem. @RialoHQ is building toward the latter before it becomes the dominant failure mode. The Langflow exploit and the cleartext API key pattern aren't edge cases. They're what happens when AI tooling gets deployed before anyone thought seriously about the security model. SCALE inside Latch means the coordination layer and the governance layer ship together rather than the governance being retrofitted after something goes wrong. That sequencing is rare and it's the right call.

    Post summary

    Langflow is under active exploitation via CVE-2026-33017, with attackers dropping Monero miners on exposed endpoints; the vulnerability is high severity (CVSS 9.3) and has been patched by Latch.

    10420871778
    9.4K followersView on X
  • مجلاد بن مشاري السبيعي@Al7lhh223
    Active Exploitation

    الحمد لله خبر يسعدني مشاركته 🙏🏻 مشروعي prompt-injection-auditor أصبح مدرجاً في CVEFeed بجانب الثغرة الحرجة CVE-2026-33017 (درجة 9.8 - تحت الإستغلال النشط) 🔥🔥 https://cvefeed.io/vuln/detail/CVE-2026-33017 والأجمل: المشروع مرتبط الآن بـ 4 ثغرات CVE في قاعدتهم - الباحثون عن أي منها يجدون أداة الدفاع في طريقهم والتقييم هناك 4.9/5 من المجتمع ⭐ http://github.com/screem500/prompt-injection-auditor #الامن_السيبراني #CyberSecurity #CVE #AISecurity

    Post summary

    The author announces their prompt-injection-auditor tool, highlights its association with the critical CVE-2026-33017 (score 9.8) marked as under active exploitation, and points to the GitHub repo and CVEFeed page, but offers no patch or exploit code.

    316075526.2K
    78.2K followersView on X
  • Hunter@HunterMapping
    Active Exploitation

    🚨Alert🚨 CVE-2026-33017 : An Unauthenticated Remote Code Execution (RCE) Vulnerability in Langflow. 📊 2.0M Services are found on the http://hunter.how yearly. 🧐PoC : https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22Langflow%22 HUNTER : http://product.name="Langflow" 📰Refer:https://thehackernews.com/2026/06/langflow-rce-exploited-to-deploy-monero.html https://medium.com/@aviral23/cve-2026-33017-how-i-found-an-unauthenticated-rce-in-langflow-by-reading-the-code-they-already-dc96cdce5896 https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces an unauthenticated RCE vulnerability (CVE‑2026‑33017) in Langflow, shares a PoC and exploitation evidence, and indicates it is actively being exploited in the wild.

    320065388.9K
    26.0K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ Langflow CVE-2026-33017 was exploited in 20 hours of disclosure. An exposed API runs attacker-supplied Python with no auth, enabling full server takeover. Real attacks show credential theft, file access, and staged payload delivery. 🔗 Read → https://thehackernews.com/2026/03/critical-langflow-flaw-cve-2026-33017.html

    Post summary

    Attacks exploiting CVE‑2026‑33017 used an unauthenticated API to run arbitrary Python, leading to credential theft and data access; the vulnerability remains in the wild with no patch or mitigation mentioned.

    21825499.7K
    1.1M followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 CVE-2026-33017 is being exploited against Langflow. Attackers abuse an unauthenticated API endpoint to run Python code, drop Lambsys, and launch a Monero miner. Lambsys can spread via reused SSH keys. Langflow attack chain: https://thehackernews.com/2026/06/langflow-rce-exploited-to-deploy-monero.html

    Post summary

    CVE-2026-33017 is actively exploited against Langflow, using an unauthenticated API endpoint to run Python code and deploy Lambsys for a Monero miner, with potential spread via reused SSH keys; detailed chain is linked in the article.

    1142531219.5K
    2.3M followersView on X
  • Brute@BRuteLogic
    General

    Patch_Diffs -> New_Bugs Langflow, an open-source tool for visually building AI agent and RAG pipelines, is another example of multiple hits by the same flaw. CVE-2025-3248: user input to exec() CVE-2026-33017: same sink, diff endpoint 1. Grep the sink, not the CVE grep -rn "exec(compiled_code" src/ 2. Find every caller of the sink grep -rln "instantiate_class" src/ 3. Map callers to HTTP endpoints grep -B15 "async def.*flow" http://chat.py Patched once, vulnerable twice.

    Post summary

    The message lists two Langflow CVEs, highlights a shared exec sink vulnerability, and shows how to locate potential vulnerable points, but provides no patches, exploits, or evidence of active exploitation.

    27034163.6K
    66.7K followersView on X
  • Ryx@PadhiyarRushi
    PoC

    Langflow is one unauthenticated request away from a reverse shell. CVE-2026-33017: /api/v1/build_public_tmp/{flow_id}/flow accepts attacker-controlled flow definitions and runs them via exec() with no sandbox. Working reverse-shell PoC is public. Exposed instances are critical risk. https://github.com/z4yd3/PoC-CVE-2026-33017 #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AgentSecurity #RCE

    Post summary

    The text reports a critical unauthenticated RCE in Langflow and emphasizes that a working reverse-shell PoC is public with a GitHub PoC link. It does not mention active exploitation or remediation.

    05033182.3K
    953 followersView on X
  • watchTowr@watchtowrcyber
    General

    Rapid reaction gets you ahead. 4 days before CISA added CVE-2026-33017 (Langflow RCE) to KEV, watchTowr clients were already aware of their exposure. Reach out via our website (http://watchTowr.com) if you need support. https://t.co/Vzx6SGim0U

    Post summary

    watchTowr notified its clients of the Langflow RCE CVE‑2026‑33017 before CISA’s KEV listing, offering support through its website.

    0604086.2K
    11.1K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Langflow code injection vulnerability CVE-2026-33017 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/DfWhyalMME

    Post summary

    The post announces that CVE-2026-33017, a code injection flaw in Langflow, has been added to DHS's Known Exploited Vulnerabilities Catalog, implying it is actively exploited, though specific exploit or patch details are not provided.

    21622646.3K
    293.3K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ One POST to RCE: Unauthenticated Code Execution in Langflow (CVE-2026-33017) https://darkwebinformer.com/one-post-to-rce-unauthenticated-code-execution-in-langflow-cve-2026-33017/

    Post summary

    The post indicates that a single POST request triggers unauthenticated remote code execution in Langflow (CVE-2026-33017), presenting a proof‑of‑concept but lacking details on exploit tools, patches, or active attacks.

    111027910.0K
    233.3K followersView on X
  • Zero Day Engineering@zerodayalpha
    Active Exploitation

    ⚡️ 0-Day Alert: IBM LangFlow OSS RCE LangFlow agent orchestration deployments have been under active exploitation since May. CVE-2025-34291: CORS misconfiguration + SameSite=None CVE-2026-33017*: Unauthenticated RCE via build_public_tmp's data parameter CVE-2026-55255: IDOR in /api/v1/responses: run any user's flow by ID CVE-2026-0770: Unauthenticated RCE via validate_code() / decorator abuse CVE-2026-9198: Unauthenticated RCE via auto_login + validate/code chain Bugs are not hard, likely spotted by generally available AI. Public exploit POCs exist. Majority takes input from an API endpoint variable and executes it directly on the OS. Attack pattern suggests that LangFlow has not seen basic security QA from the developer, and shouldn't be deployed in environments where arbitrary code execution poses a risk. * Attached: 33017 patch diff and code trace to exec()

    Post summary

    IBM LangFlow deployments are being actively exploited via multiple CVEs, including RCEs and IDORs, with public PoCs available and a patch referenced for at least one vulnerability.

    17022103.2K
    11.8K followersView on X
  • Co11ateral@co11ateral
    PoC

    CVE-2026-33017 - Langflow Unauthenticated RCE Langflow is a tool for building and deploying AI agents and MCP servers. https://github.com/MaxMnMl/langflow-CVE-2026-33017-poc #redteam #ai #cybersecurity

    Post summary

    The post announces CVE‑2026‑33017 for an unauthenticated RCE in Langflow and shares a PoC repository, but it contains no evidence of active exploitation or available patches.

    07019131.8K
    4.7K followersView on X
  • /r/netsec@_r_netsec
    Active Exploitation

    Langflow Got Hacked Twice Through the Same exec() Call - CVE-2026-33017 (CVSS 9.3) exploited in 20 hours with no public PoC https://blog.barrack.ai/langflow-exec-rce-cve-2026-33017/

    Post summary

    The blog post reports that CVE‑2026‑33017, a RCE in Langflow with CVSS 9.3, was actively exploited in the wild within 20 hours, and that no public PoC exists.

    26114111.8K
    32.9K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    Code review case study: finding CVE-2026-33017 in Langflow https://medium.com/@aviral23/cve-2026-33017-how-i-found-an-unauthenticated-rce-in-langflow-by-reading-the-code-they-already-dc96cdce5896

    Post summary

    The Medium article reports the discovery of CVE-2026-33017, an unauthenticated remote code execution in Langflow, focusing on the initial findings rather than exploitation or patching.

    1601672.1K
    153.4K followersView on X
  • Sysdig@sysdig
    Active Exploitation

    🚨 Less than a day after the disclosure of CVE-2026-33017, a critical unauthenticated RCE in Langflow, attackers were already exploiting it in the wild. Read the full breakdown👇 https://okt.to/LJ1HQr https://t.co/KCHNHlTtwo

    Post summary

    A critical, unauthenticated RCE in Langflow (CVE‑2026‑33017) was reportedly being exploited in the wild shortly after disclosure.

    0601441.3K
    10.3K followersView on X
  • Dark Web Informer@DarkWebInformer
    Disclosure

    ‼️ CISA has added 1 vulnerability to the KEV Catalog. CVE-2026-33017: Langflow Code Injection Vulnerability https://darkwebinformer.com/cisa-kev-catalog/

    Post summary

    CISA has added CVE-2026-33017, a Langflow code injection vulnerability, to its KEV catalog, but the post provides no further technical, exploit, or mitigation details.

    1501254.7K
    182.5K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    Langflow's public flow endpoint passes user-supplied Python directly to exec() with zero sandboxing. Attackers exploited it in 20 hours. This is the second time the same exec() call was the root cause. https://blog.barrack.ai/langflow-exec-rce-cve-2026-33017/

    Post summary

    CVE‑2026‑33017 in Langflow was actively exploited within 20 hours, leveraging an unsandboxed exec() call; no patch information is provided in the text.

    1401232.5K
    153.4K followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-33017 (CVSS 9.3): Unauth RCE in Langflow public flow builds. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJMT0dTUEFDRS1MYW5nRmxvdyI= 🎯3K+ results last year. FOFA Query: app="LOGSPACE-LangFlow" 🔖Refer: https://github.com/advisories/GHSA-vwmf-pq79-vjvx #OSINT #FOFA #CyberSecurity #Vulnerability https://t.co/GGTtujFrIR

    Post summary

    The tweet announces the disclosure of CVE-2026-33017, a high‑severity (CVSS 9.3) unauthenticated RCE affecting Langflow public flow builds, providing FOFA query details and a reference to a GitHub advisory.

    0501221.6K
    13.7K followersView on X
  • Wazuh@wazuh
    Disclosure

    CVE-2026-33017 (CVSS 9.8) is a critical, unauthenticated remote code execution vulnerability in Langflow that lets a single POST request execute arbitrary Python code. Our latest blog post shows how to detect exploitation with Wazuh. Read on: https://ow.ly/ini850ZBZkm

    Post summary

    The post announces CVE‑2026‑33017, a critical unauthenticated RCE in Langflow allowing arbitrary Python code execution via a single POST request, and references a blog for detection methods.

    08090655
    8.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applangflowlangflow---

Explore more