Cyberpress
Langflow AI CSV Agent Vulnerability Enables Remote Code Execution
First seen 2 Mar 2026, 15:11 UTC
•

•51.6
Export
Article Content
Browse articles
A security researcher disclosed a vulnerability (GHSA-3645-fxcv-hqr4) in the Langflow package on PyPI, which allows remote code execution attacks. The flaw specifically affects the CSV agent functionality within the open-source Langflow AI framework. Users of this package are advised to review their implementations and apply necessary mitigations.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-25
GHSA-3645-fxcv-hqr4 disclosed by researcher Empreiteiro
2026-03-02
Articles published detailing the Langflow vulnerability
More articles in this cluster
Continue Reading
Critical RCE Vulnerability in IBM Langflow Under Active Exploitation
CISA Warns of Critical Exploits in Langflow, Tomcat, and N-central Flaws
Russian Hackers Target Networks via RDP, VPNs, and Supply Chains
Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
Langflow CVE-2026-33017 Exploited for AWS Key Theft and Botnet Deployment