Frequency
7
occurrences
First Seen
April 7, 2026
Last Seen
April 8, 2026
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—
Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
A critical remote code execution (RCE) vulnerability in the Flowise low-code platform, tracked as CVE-2025-59528, is being actively exploited by threat actors. This flaw allows attackers to inject arbitrary JavaScript code due to improper validation of user input in the CustomMCP node, which connect...
A critical vulnerability in Langflow, tracked as CVE-2026-33017, allows unauthenticated remote code execution (RCE) via the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint. This flaw was exploited within 20 hours of its disclosure on March 20, 2026, with the first successful data exfiltration...
Public Exploits
Checking GitHub for proof-of-concept code…
Related Clusters (2)
Related Articles (7)
1 / 2