Langflow RCE Flaw Lets Attackers Execute Arbitrary Python Code Without Authentication
ID: ce671bf8-8c24-5b9b-a0ab-7ce996a19f3d
STIX ID: report--ce671bf8-8c24-5b9b-a0ab-7ce996a19f3d
Feed Name: GBHackers
A critical unauthenticated RCE (CVE-2026-33017) in Langflow is being actively exploited within hours of disclosure via the public POST /api/v1/build_public_tmp/{flow_id}/flow endpoint, allowing attackers to inject and execute arbitrary Python code. Attackers used automated scanners (Nuclei), Interactsh OOB callbacks for exfiltration, and hosted C2/dropper infrastructure to deliver stage-2 payloads; observed actions include directory listing, reading /etc/passwd, searching for .env/database files, and credential harvesting, posing significant risk to AI integrations and downstream supply chains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
