logo

CISA: New Langflow flaw actively exploited to hijack AI workflows

ID: 2f1be909-f4e7-5153-9a73-6f15e7c5bc36

STIX ID: report--2f1be909-f4e7-5153-9a73-6f15e7c5bc36

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-03-26

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CISA warns that CVE-2026-33017, a critical (CVSS 9.3) code-injection flaw in the Langflow AI workflow framework, is being actively exploited in the wild—allowing attackers to execute arbitrary Python code, create public flows without authentication, and harvest sensitive files (.env, .db). Researchers observed automated scanning and exploitation within ~24 hours of disclosure; CISA added the issue to Known Exploited Vulnerabilities and advised affected organizations (federal and otherwise) to upgrade to Langflow 1.9.0 or apply mitigations, restrict exposure, and rotate secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.