logo

U.S. CISA adds a Langflow flaw to its Known Exploited Vulnerabilities catalog

ID: d9d6ad18-7aa2-535b-a735-222cdddbea4a

STIX ID: report--d9d6ad18-7aa2-535b-a735-222cdddbea4a

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA has added a critical Langflow vulnerability (CVE-2026-33017, CVSS 9.3) to its Known Exploited Vulnerabilities catalog: the unauthenticated POST /api/v1/build_public_tmp/{flow_id}/flow endpoint can execute attacker-supplied Python code via exec(), leading to remote code execution and potential full system compromise; federal agencies must remediate by April 8, 2026. The report also references a prior similar Langflow RCE (CVE-2025-3248).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.