CVE-2026-33017: How attackers compromised Langflow AI pipelines in 20 hours
ID: 05ae8ca2-4f8f-5c3c-879e-f3cd2f973b64
STIX ID: report--05ae8ca2-4f8f-5c3c-879e-f3cd2f973b64
Feed Name: Sysdig Blog
Threat Score
**Executive summary:** CVE-2026-33017 is an unauthenticated RCE in Langflow's public flow build endpoint that was actively exploited within ~20 hours of disclosure; attackers scanned broadly, executed arbitrary Python to collect environment variables and credentials, staged second-stage payloads, and exfiltrated secrets to identified C2 infrastructure, with multiple source IPs and interactsh callbacks observed across a honeypot fleet.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
