logo

Critical Flaw in Langflow AI Platform Under Attack

ID: d805e02c-6150-5b49-89f4-074fef0230f8

STIX ID: report--d805e02c-6150-5b49-89f4-074fef0230f8

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

Author: Rob Wright

...
...

A critical unauthenticated code-injection vulnerability (CVE-2026-33017, CVSS 9.8) in the Langflow AI-agent framework was disclosed and observed being exploited within 24 hours; attackers could supply attacker-controlled flow data that gets executed via exec(), enabling remote code execution, extraction of API keys/credentials, and potential lateral movement. Langflow released version 1.9.0 to mitigate the issue and researchers warn that rapid exploitation of open-source AI tooling is becoming common, urging rapid patching, runtime detection, and network segmentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.