Scmagazine Critical Langflow RCE Vulnerability Exploited Within 20 Hours
Article Content
- •CVE-2026-33017 allows unauthenticated RCE in Langflow, affecting public flow builds.
- •Exploitation attempts were detected within 20 hours of the vulnerability's disclosure.
- •The vulnerability has a CVSS score of 9.3, indicating a critical threat level.
A critical vulnerability in Langflow, tracked as CVE-2026-33017, allows unauthenticated remote code execution (RCE) via the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint. This flaw was exploited within 20 hours of its disclosure on March 20, 2026, with the first successful data exfiltration occurring shortly after 25 hours. Attackers can send crafted HTTP requests containing arbitrary Python code that executes server-side without sandboxing. The vulnerability affects users of Langflow, a popular open-source framework for building AI workflows, which has over 145,000 stars on GitHub. Sysdig reported that attackers are leveraging this vulnerability to pivot into connected AI pipelines, potentially harvesting sensitive API keys and database credentials. The CVSS score for this vulnerability is 9.3, indicating its critical nature. The issue was patched in version 1.9.0 of Langflow. No public exploits were reported prior to the vulnerability's disclosure, but exploitation attempts were quickly observed. Organizations using Langflow are at risk of significant data loss and system compromise.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (17)
Following this threat?
Track Langflow and CVE-2025-3248 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI-Discovered Vulnerabilities Surge, Increasing RCE Threats Google's Threat Intelligence Group (GTIG) reports that software vulnerability disclosures doubled from 5,045 in January 2026 to 10,740 in August 2026, largely influenced by AI-assisted discovery. Notably, 50% of AI-discovered vulnerabilities enable remote code execution (RCE), compared to 26% of non-AI…