Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-catalograpid-weaponizationai-platform-security

Actively Exploited Langflow RCE Exposed AI Pipeline Secrets and Triggered CISA KEV Listing

Updated 17d agoFirst seen Mar 20, 202613 sources

Threat actors rapidly exploited CVE-2026-33017, a critical unauthenticated remote code execution flaw in Langflow’s public flow build endpoint, allowing arbitrary Python code to reach an unsandboxed exec() path with a single crafted request. The bug affects Langflow versions prior to 1.9.0 and stems from the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint accepting attacker-controlled flow data through an optional parameter. Researchers and vendor advisories said the issue is distinct from CVE-2025-3248 because the vulnerable endpoint is intentionally public, meaning the fix required removing attacker-supplied flow data from that execution path rather than simply adding authentication.

Sysdig and other researchers reported exploitation beginning within about 20 hours of disclosure, with attackers scanning for exposed instances, validating code execution, reading files such as .env, .db, and /etc/passwd, stealing credentials, API keys, and database secrets, and attempting follow-on payload delivery from infrastructure including 173.212.205[.]251:8443. The severity prompted CISA to add the flaw to its Known Exploited Vulnerabilities catalog and order federal agencies to remediate by April 8, 2026 or discontinue use if they could not secure affected systems. Security guidance across the reports urged organizations to upgrade to Langflow 1.9.0 or later, restrict or remove internet exposure of the vulnerable endpoint, monitor outbound connections, and rotate secrets if compromise is suspected.

Share:
Actively Exploited Langflow RCE Exposed AI Pipeline Secrets and Triggered CISA KEV Listing
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Apr 8, 20263mo ago

CISA orders federal agencies to remediate by April 8

After adding the flaw to KEV, CISA directed Federal Civilian Executive Branch agencies to remediate CVE-2026-33017 by April 8, 2026. Guidance also said agencies should discontinue use if mitigations could not be applied.

Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
Mar 25, 20263mo ago

CISA adds CVE-2026-33017 to the KEV catalog

CISA added the Langflow flaw to its Known Exploited Vulnerabilities catalog after determining it was being actively exploited in the wild. The agency's action elevated the issue for federal defenders and the broader security community.

Critical Langflow AI bug exploited within 20 hours added to CISA list | news | SC Media
Mar 24, 20263mo ago

ProjectDiscovery opens PR for Nuclei detection template

A pull request was opened to add a Nuclei template for CVE-2026-33017. Review comments pushed the template from passive version checks toward an actual POST-based proof-of-concept detection method, and the author updated it accordingly.

Added Nuclei Template for CVE-2026-33017 (Langflow RCE) by himind · Pull Request #15670 · projectdiscovery/nuclei-templates · GitHub
Mar 23, 20263mo ago

Belgium's CCB issues warning to patch Langflow immediately

Belgium's Centre for Cybersecurity published an advisory warning about the critical Langflow vulnerability and urging immediate patching. This reflected growing government concern over the flaw's risk to AI pipeline deployments.

Warning: Critical vulnerability in Langflow AI pipelines. Patch Immediately! | CCB Safeonweb
Mar 20, 20263mo ago

Langflow fix is available in version 1.9.0

Multiple references state the vulnerability was fixed in Langflow version 1.9.0, with earlier development builds also addressing it. The remediation removed the unsafe attacker-controlled path in the public flow build process.

CVE-2026-33017 - Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
Mar 19, 20263mo ago

Sysdig publishes attack analysis of Langflow exploitation

Sysdig released a report detailing how attackers compromised Langflow AI pipelines in about 20 hours. The company described six source IPs, staged payload delivery, credential theft, and use of custom tooling and shared infrastructure.

CVE-2026-33017: How attackers compromised Langflow AI pipelines in 20 hours | Sysdig

Attackers begin exploiting CVE-2026-33017 within 20 hours

Sysdig observed exploitation attempts roughly 20 hours after disclosure, showing attackers weaponized the flaw without a public proof-of-concept. Activity included scanning, RCE validation, reconnaissance, payload delivery, and credential harvesting.

CVE-2026-33017: How attackers compromised Langflow AI pipelines in 20 hours | Sysdig
Mar 18, 20263mo ago

Sysdig honeypots detect exploitation attempts

Sysdig detected exploitation attempts against honeypots on March 18, indicating active abuse of the Langflow flaw shortly after disclosure. The observed attacks targeted secrets, credentials, and files tied to AI pipelines.

Critical Langflow AI bug exploited within 20 hours added to CISA list | news | SC Media
Mar 17, 20263mo ago

CVE-2026-33017 is disclosed and assigned

CVE-2026-33017 was publicly disclosed for Langflow's public flow build endpoint, with reports stating disclosure occurred on March 17, 2026. GitHub also assigned the CVE on that date according to later reporting.

CVE-2026-33017: How attackers compromised Langflow AI pipelines in 20 hours | Sysdig
Mar 16, 20263mo ago

Langflow publishes security advisory for CVE-2026-33017

Langflow published GitHub advisory GHSA-vwmf-pq79-vjvx describing a critical unauthenticated remote code execution flaw in the public flow build endpoint. The advisory explained that attacker-supplied flow data could reach an unsandboxed exec() path.

Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint · Advisory · langflow-ai/langflow · GitHub
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

32 LINKEDOpen in app
Malware
1 linked
Affected products
6 linked
LangflowLangflowNucleiAmazon Web ServicesFalcoN8n
Organizations
22 linked
SysdigColorTokensSectigoBugcrowdLangflowAnthropicOpenaiAmazon Web ServicesGitHubProjectdiscoveryRapid7Horizon3.aiDigitaloceanDark ReadingAccentureSC MediaAEZA GroupEndor LabsContaboSecurity AffairsAcalvioPUSHPKT OU
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.