logo

Langflow Flodrix vulnerability CVE-2026–33017: Find impacted assets

ID: 9beb120a-504b-57ca-9c6e-c42b231eafed

STIX ID: report--9beb120a-504b-57ca-9c6e-c42b231eafed

Feed Name: runZero Blog

Threat Score
85/100

Date Published: 2025-05-06

Date Updated: 2026-04-29

Author: Tom Sellers

...
...

Two critical RCE vulnerabilities in Langflow are described: CVE-2026-33017 (CVSS 9.3) affecting versions prior to 1.8.2 and CVE-2025-3248 (CVSS 9.8) affecting versions prior to 1.3.0. The CVE-2025-3248 issue has confirmed active exploitation in the wild as part of a campaign that uses a public proof-of-concept to deploy the Flodrix botnet; Langflow has released patched versions and users are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.