logo

CISA Warns of Langflow Code Injection Vulnerability Exploited in Attacks

ID: c6330e6d-e279-5b65-81f6-76fca59d8f4d

STIX ID: report--c6330e6d-e279-5b65-81f6-76fca59d8f4d

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-03-26

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Executive Summary:** CISA added CVE-2026-33017, a critical unauthenticated code-injection vulnerability in the Langflow low-code AI workflow platform, to its Known Exploited Vulnerabilities catalog on March 25, 2026; the flaw is actively being exploited and allows remote attackers to build and execute public flows without credentials, enabling data theft, workflow manipulation, and lateral movement—CISA mandates rapid remediation or discontinuation until a verified fix is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.