logo

Langflow RCE Flaw Lets Attackers Execute Arbitrary Python Code Without Authentication

ID: ce671bf8-8c24-5b9b-a0ab-7ce996a19f3d

STIX ID: report--ce671bf8-8c24-5b9b-a0ab-7ce996a19f3d

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

Author: Divya

...
...

A critical unauthenticated RCE (CVE-2026-33017) in Langflow is being actively exploited within hours of disclosure via the public POST /api/v1/build_public_tmp/{flow_id}/flow endpoint, allowing attackers to inject and execute arbitrary Python code. Attackers used automated scanners (Nuclei), Interactsh OOB callbacks for exfiltration, and hosted C2/dropper infrastructure to deliver stage-2 payloads; observed actions include directory listing, reading /etc/passwd, searching for .env/database files, and credential harvesting, posing significant risk to AI integrations and downstream supply chains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.