Endorlabs Critical Vulnerabilities Discovered in AI Orchestration Platforms
Article Content
- •14 critical vulnerabilities identified across seven AI orchestration platforms.
- •Vulnerabilities allow unauthenticated users to execute code remotely.
- •Research findings emphasize the need for improved security in multi-tenant environments.
Research presented at DEFCON 34 revealed 14 critical and high severity vulnerabilities across seven AI orchestration platforms, including NocoBase, Flowise, Langflow, Dify, Activepieces, Kestra, and Apache Airflow. These platforms, integral for building AI agents and automating workflows, operate under the dangerous assumption that any user who can access a workflow is trusted to execute code on the host. Attack vectors include unauthenticated prompt injections leading to remote code execution (RCE), with some platforms allowing exploitation without user authentication. Notably, Flowise's vulnerability chain involves unauthenticated requests that can lead to RCE through pre-imported libraries. The findings highlight a significant security oversight in multi-tenant environments designed as single-user tools, where sensitive information can be compromised. The full technical whitepaper detailing these vulnerabilities has been made publicly available.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Langflow in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…