CVE detail
CVE-2026-33017
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 4.6
Why it matters now
Mention timeline
- Total mentions
- 6
- within the 30d window
- Peak daily
- 2
- highest bucket
Evidence
Source links by recency
38 source links · newest first
a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the [official 6.5 release blog post](https://www.rapid7.com/blog/po
vendorwww.rapid7.comAug 14, 2026, 9:27 PMepSeek work through an actual attack chain is the most striking part of the report. It found a Langflow vulnerability ( CVE-2026-33017 ), downloaded a public proof-of-concept, scanned for 84 live instances, and hit a wall: every target needed either a public flow ID or a login setting the attacker didn’t have access to. Rather than giving up, DeepSeek
newssecurityaffairs.comAug 3, 2026, 3:52 PM- Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability ExploitsInfosecurity Magazine
ritizing vulnerabilities by attack surface. This research led the agent to pivot to seven higher-value vulnerabilities: CVE-2026-33017 (CVSS rating: 9.8): Langflow vulnerability with autonomous exploitation attempt (failed — auto_login disabled) CVE-2026-21858 (CVSS rating: 10.0): n8n Workflow Automation vulnerability with autonomous exploitation attem
newswww.infosecurity-magazine.comJul 31, 2026, 3:00 PM - ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More StoriesThe Hacker News
rrying out an AI-enabled autonomous hacking campaign, targeting infrastructure using seven vulnerabilities in Langflow (CVE-2026-33017), n8n (CVE-2026-21858, CVE-2025-68613), Citrix NetScaler (CVE-2026-3055), Apache Tomcat (CVE-2026-34486), Marimo Notebook (CVE-2026-39987), Palo Alto Networks PAN-OS (CVE-2026-0300), and Microsoft Windows IKE Extensions
newsthehackernews.comJul 30, 2026, 3:25 PM task. Figure 1. Autonomous attack flow observed in Hermes Agent session (May 7, 2026). Phase 1: Langflow Exploitation (CVE-2026-33017) DeepSeek identified a Langflow vulnerability ( CVE-2026-33017 , CVSS 9.8) and autonomously attempted exploitation through the following steps: Downloading the public PoC exploit from GitHub Enumerating 84 Langflow inst
vendorunit42.paloaltonetworks.comJul 30, 2026, 10:00 AMcode endpoint without authentication, allowing any remote attacker to execute arbitrary Python on the server. The flaw, CVE-2025-3248 , carries a CVSS score of 9.8 and has been in CISA's Known Exploited Vulnerabilities catalog since May 5, 2025. As The Hacker News reported earlier this month, the prior operation used throwaway Python code and MySQL's
newsthehackernews.comJul 21, 2026, 7:34 AMThe US Cybersecurity and Infrastructure Security Agency (CISA) is warning about yet another Langflow vulnerability (CVE-2026-55255) leveraged by attackers in the wild. The flaw was added to the agency’s Known Exploited Vulnerabilities catalog on Tuesday, July 7, nearly two weeks after the Sysdig Threat Research Team observed it being actively targeted. CVE-2026-55255 exploited Langflow is an open-source visual framework for building AI agents and workflows, widely used by individual developers, enterprises, and service providers. CVE-2026-55255 … More →
newswww.helpnetsecurity.comJul 8, 2026, 2:03 PMat vulnerabilities in Adobe ColdFusion, Langflow, and two Joomla extensions have been exploited in the wild. Tracked as CVE-2026-48282 (CVSS score of 10/10), the ColdFusion bug was flagged as exploited only days after Adobe rolled out patches for it on June 30. It is a path traversal issue that allows attackers to execute arbitrary code. The Langflow s
newswww.securityweek.comJul 8, 2026, 10:45 AMg-and-drop interface to connect nodes into executable pipelines and a REST API to run them programmatically. Tracked as CVE-2026-55255 , this Insecure Direct Object Reference (IDOR) security flaw allows authenticated threat actors to access other users' flows by sending a maliciously crafted request to the /api/v1/responses endpoint with the victim's U
newswww.bleepingcomputer.comJul 8, 2026, 9:58 AMShaper SP Page Builder flaws to its Known Exploited Vulnerabilities (KEV) catalog . The flaws added to the catalog are: CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled
newssecurityaffairs.comJul 8, 2026, 8:38 AM- [webapps] Langflow 1.9.0 - RCEExploit-DB
eadTimeout : print ( "[+] Shell is done" ) parser = argparse . ArgumentParser ( description = "Exploit for Langflow RCE CVE-2026-33017" ) parser . add_argument ( '-l' , '--lhost' , required = True , help = "Attacker local ip address." ) parser . add_argument ( '-p' , '--lport' , required = True , help = "Attacker local port." ) parser . add_argument (
exploitwww.exploit-db.comJul 8, 2026, 12:00 AM - SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 104Security Affairs
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer Building a CI/CD pipeline for Sigma rules Inside StegoAd: How a Threat Actor Evolved to Fuel Silent Ad […]
newssecurityaffairs.comJul 5, 2026, 5:37 PM - 22nd June – Threat Intelligence ReportCheck Point Research
rs showed how game-like prompts could expose credentials and user data. VULNERABILITIES AND PATCHES Cisco has addressed CVE-2026-20245, a high-severity command injection flaw in Catalyst SD-WAN Manager that attackers exploited as a zero-day for months. The flaw allows an administrator to run root commands through a crafted file, affecting on-premises a
vendorresearch.checkpoint.comJul 1, 2026, 11:29 AM ty as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI)
newsthehackernews.comJun 30, 2026, 3:47 PM- 29th June – Threat Intelligence ReportCheck Point Research
rs showed how game-like prompts could expose credentials and user data. VULNERABILITIES AND PATCHES Cisco has addressed CVE-2026-20245, a high-severity command injection flaw in Catalyst SD-WAN Manager that attackers exploited as a zero-day for months. The flaw allows an administrator to run root commands through a crafted file, affecting on-premises a
vendorresearch.checkpoint.comJun 29, 2026, 2:06 PM - From Langflow to Monero: Inside CVE-2026-33017 CryptominerTrend Micro Research
We tracked a cryptocurrency-mining campaign exploiting CVE-2026-33017, which revealed how threat actors are now scanning exposed AI application infrastructure for their next foothold.
vendorwww.trendmicro.comJun 23, 2026, 12:00 AM - PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVMTrend Micro Research
forgery (SSRF) in the PSIGW gateway, then gains code execution through Java XMLDecoder deserialization. Oracle assigned CVE-2026-35273 open on a new tab (CVSS 9.8) and released an out-of-band patch on June 10, 2026. The chain affects PeopleTools 8.61, and 8.62, including installations that were fully patched before the out-of-band advisory, because Ora
vendorwww.trendmicro.comJun 18, 2026, 12:00 AM - Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown YetTrend Micro Research
Related Articles TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry From Langflow to Monero: Inside CVE-2026-33017 Cryptominer PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM See all articles Trend Vision One™ one-platform - Proactive Security Starts Here. Resources Blog Newsroom news a
vendorwww.trendmicro.comJun 1, 2026, 12:00 AM - Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in AsiaTrend Micro Research
d them targeting server-based N-day vulnerabilities, such as the ProxyLogon chain targeting Microsoft Exchange Server ( CVE-2021-26855 , CVE-2021-26857 , CVE-2021-26858 , and CVE-2021-27065 ). Despite their age, these vulnerabilities remain effective exploits in unpatched environments. After compromising the server, the group used their access to insta
vendorwww.trendmicro.comApr 30, 2026, 12:00 AM - Identity Protection in the AI EraTrend Micro Research
Related Articles TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry From Langflow to Monero: Inside CVE-2026-33017 Cryptominer PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM See all articles Trend Vision One™ one-platform - Proactive Security Starts Here. Resources Blog Newsroom news a
vendorwww.trendmicro.comApr 13, 2026, 12:00 AM - CVE-2026-39987: Marimo RCE exploited in hours after disclosureSecurity Affairs
A critical flaw, tracked as CVE-2026-39987, in the open-source Python notebook tool Marimo was exploited within 10 hours of disclosure. A critical flaw in Marimo, tracked as CVE-2026-39987 (CVSS score of 9.3) was exploited just 10 hours after disclosure (On April 8, 2026). Sysdig Threat Research Team observed exploitation of the Marimo flaw within 9 […]
newssecurityaffairs.comApr 11, 2026, 9:44 AM - The Real Risk of VibecodingTrend Micro Research
Related Articles TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry From Langflow to Monero: Inside CVE-2026-33017 Cryptominer PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM See all articles Trend Vision One™ one-platform - Proactive Security Starts Here. Resources Blog Newsroom news a
vendorwww.trendmicro.comMar 31, 2026, 12:00 AM - Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packagesHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: NIST updates its DNS security guidance for the first time in over a decade DNS infrastructure underpins nearly every network connection an organization makes, yet security configurations for it have gone largely unrevised at the federal guidance level for more than twelve years. NIST published SP 800-81r3, the Secure Domain Name System Deployment Guide, superseding a version that dates to … More →
newswww.helpnetsecurity.comMar 29, 2026, 8:00 AM Attackers have exploited a critical Langflow RCE within hours of disclosure, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to formally flag it for urgent remediation. The flaw, which allows running arbitrary code on vulnerable Langflow instances without credentials, was weaponized within 20 hours of the open-source AI-pipeline tool disclosing it. According to a Sysdig report, […]
newswww.csoonline.comMar 27, 2026, 12:03 PM- CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitationHelp Net Security
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33017, a recently disclosed code injection vulnerability in Langflow, an open-source framework for building AI agents and workflows, and CVE-2026-33634, an embedded malicious code vulnerability in Aqua Security’s Trivy security scanner. Their addition to the catalog means that US federal civilian agencies are required to address the flaws within their networks by April 8 and 9, … More →
newswww.helpnetsecurity.comMar 27, 2026, 10:43 AM The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Langflow to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Langflow flaw, tracked as CVE-2026-33017 (CVSS score of 9.3), to its Known Exploited Vulnerabilities (KEV) catalog. Langflow is a popular tool used for building agentic AI workflows. CVE-2026-33017 is a […]
newssecurityaffairs.comMar 26, 2026, 9:05 PM- Your AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain CompromiseTrend Micro Research
ance security concerns with backwards compatibility. This isn't the first exploitation: Volexity observed .pth abuse in CVE-2024-3400 exploitation. The npm track (checkmarx-util-1.0.4) followed an identical pattern but targeted DevSecOps engineers through a fake Checkmarx utility package. It was served directly from attacker-controlled infrastructure
vendorwww.trendmicro.comMar 26, 2026, 12:00 AM - Your AI Stack Just Handed Over Your Root Keys: Inside the litellm PyPI BreachTrend Micro Research
Related Articles TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry From Langflow to Monero: Inside CVE-2026-33017 Cryptominer PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM See all articles Trend Vision One™ one-platform - Proactive Security Starts Here. Resources Blog Newsroom news a
vendorwww.trendmicro.comMar 25, 2026, 12:00 AM - 23rd March – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 23rd March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Navia Benefit Solutions, a United States-based employee benefits administrator, has disclosed a breach affecting more than 2.6 million individuals after unauthorized access and potential data exfiltration occurred between December 22, 2025 and […]
vendorresearch.checkpoint.comMar 23, 2026, 1:38 PM Because attacker-supplied flow data is used in public flows, the bug leads to unauthenticated remote code execution.
newswww.securityweek.comMar 20, 2026, 8:38 AM- https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hourswww.sysdig.com
No excerpt available.
Exploitwww.sysdig.comMar 20, 2026, 5:16 AM No excerpt available.
Mitigationwww.cisa.govMar 20, 2026, 5:16 AMNo excerpt available.
Exploitmedium.comMar 20, 2026, 5:16 AMNo excerpt available.
Exploitgithub.comMar 20, 2026, 5:16 AMNo excerpt available.
Exploitgithub.comMar 20, 2026, 5:16 AMNo excerpt available.
Exploitgithub.comMar 20, 2026, 5:16 AMNo excerpt available.
Exploitgithub.comMar 20, 2026, 5:16 AM- Why East-West Visibility Matters for Grid SecurityTrend Micro Research
Related Articles TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry From Langflow to Monero: Inside CVE-2026-33017 Cryptominer PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM See all articles Trend Vision One™ one-platform - Proactive Security Starts Here. Resources Blog Newsroom news a
vendorwww.trendmicro.comMar 18, 2026, 12:00 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
1 repository references · best confidence 0.80 · max 1 stars
- Industri4l-H3ll-Xpl0it3rs/CVE-2026-33017-Langflow-RCEMedium confidencegithubRepository topic discovery1 starsDiscovered Jul 16, 2026, 6:51 PM
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-3248CVSS 9.8 · Critical
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to…
- CVE-2026-65941CVSS 8.8 · High
In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the…
- CVE-2026-73248CVSS 8.5 · High
calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program:…
- CVE-2026-72904CVSS 9.3 · Critical
Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functio…
- CVE-2026-46409CVSS 9.6 · Critical
OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API…
- CVE-2026-71319CVSS 9.6 · Critical
Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket…