Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
ID: fd7b074b-8a38-502b-abb1-567a98641af5
STIX ID: report--fd7b074b-8a38-502b-abb1-567a98641af5
Feed Name: The Hacker News
A critical unauthenticated remote code execution vulnerability (CVE-2026-33017, CVSS 9.3) in Langflow allowed attackers to supply Python code to an endpoint that calls exec(), enabling immediate RCE; proof of active exploitation was observed within 20 hours of disclosure with attackers scanning for vulnerable instances, exfiltrating keys/credentials, harvesting environment variables and configuration files, and delivering follow-on payloads from a hosted IP address. Users are advised to upgrade, rotate secrets, audit exposed instances, monitor outbound connections, and restrict access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
