CVE-2026-33017: Langflow Code Injection Vulnerability. Langflow contains a
Langflow Code Injection Vulnerability. Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication.
- CISA KEV-listed (remediation due 2026-04-08)
- EPSS 99.8% (100.0% percentile)
- CVSS 9.3 critical
Related briefings
- A hacker let an AI agent pick and attack its own targets 2026-07-30
- Hackers hijack exposed Langflow AI servers to mine cryptocurrency 2026-06-24