Skip to content

Langflow CVE-2026-33017 Exploited to Steal AWS Keys, Deploy NATS Worker

Gbhackers •Mayura Kathir • May 14, 2026

Langflow instances left unpatched against CVE-2026-33017 are now being actively abused not just for remote code execution, but as launchpads to steal AWS keys and join a NATS-backed botnet-style worker pool dubbed “KeyHunter.” The vulnerability, now listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog, affects Langflow public flow-building endpoint and allows arbitrary Python execution without […]

Extracted Entities

Attack Types (1)

Companies (1)

Malware (1)

MITRE ATT&CK (1)

Platforms (1)