
A serious security vulnerability in Langflow is being actively exploited very quickly after it was made public. This shows how fast attackers are using new vulnerabilities.
The flaw, identified as CVE-2026-33017 (with a severity score of 9.3), involves missing security checks and a way to inject code, potentially allowing attackers to remotely run code.
Langflow’s advisory explains that “The POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication.”
The advisory continues: “Using data supplied by an attacker allows the insertion of arbitrary Python code into node definitions instead of using data stored in the database. Because this unvetted code is executed with zero sandboxing using the function exec(), unauthenticated remote code execution is possible.”
This vulnerability affects all versions of this open-source AI platform up to and including version 1.8.1. It has been fixed in the development version 1.9.0.dev8.
Aviral Srivastava, the security researcher who found and reported the bug on February 26, 2026, clarified that it’s different from CVE-2025-3248 (severity score: 9.8), another serious Langflow bug. That bug used the /api/v1/validate/code endpoint to run arbitrary Python code without needing authentication. According to CISA, CVE-2025-3248, has also been actively exploited.
“CVE-2026-33017 is in /api/v1/build_public_tmp/{flow_id}/flow,” Srivastava said. He added that the problem is that the same exec() function is used as in CVE-2025-3248.
“This endpoint is meant to be unauthenticated because it serves public flows. Simply adding authentication isn’t a fix, because it would break the entire public flows feature. A better option is to remove the data parameter from this public endpoint completely, so that these public flows only execute server-stored data and reject any user-supplied definitions.”
If exploited, an attacker could send a single HTTP request to execute arbitrary code with the full rights of the server. Then, the attacker could access environment variables, modify files to inject backdoors or erase sensitive data, and even open a reverse shell.
The cloud security firm Sysdig reported seeing the first attempts to exploit CVE-2026–33017 in the real world only 20 hours after the advisory was released on March 17, 2026.
Sysdig noted that, “No public proof-of-concept (PoC) code existed at the time. Attackers created working exploits directly from the advisory and started scanning the internet for vulnerable sites. The stolen information included keys and credentials, which allowed access to connected databases and potential supply chain compromises.”
Attackers have also moved from automated scanning to using custom Python scripts to get data from “/etc/passwd” and deliver a next-stage payload hosted on “173.212.205[.]251:8443” to steal credentials. This suggests that the attackers had prepared their malware beforehand to deliver it as soon as they found a vulnerable target.
Sysdig added, “This is an attacker with an exploitation toolkit that is quickly validating vulnerabilities and delivering payloads in a single session.” The identity of the attackers is unknown.
The fact that exploitation began within 20 hours of the advisory release reflects a trend of shrinking time-to-exploit (TTE), which has fallen from a median of 771 days in 2018 to just hours in 2024.
According to Rapid7’s 2026 Global Threat Landscape Report, the median time between a vulnerability’s publication and its inclusion in CISA’s KEV catalog fell from 8.5 days to five days over the past year.
The report states, “This compressed timeline presents serious challenges to defenders. The median time for organizations to patch vulnerabilities is about 20 days, meaning defenders are exposed and vulnerable for too long. Attackers monitor the same advisories as defenders and are building exploits faster than most organizations can assess, test, and apply patches. Organizations must fundamentally change their vulnerability management programs to reflect this reality.”
Users are advised to update to the latest patched version as soon as possible. They should also review environment variables and secrets on public-facing Langflow instances, change keys and database passwords as a precaution, monitor for unusual outbound connections, and restrict network access to Langflow instances using firewalls or reverse proxies with authentication.
The exploitation of CVE-2025–3248 and CVE-2026-33017 highlights how AI workloads are being targeted by attackers because of their access to valuable data, connections to the software supply chain, and inadequate security.
Sysdig concluded: “CVE-2026-33017 demonstrates a growing trend: critical vulnerabilities in popular open-source tools are exploited within hours of disclosure, often before public proof-of-concept code is available.”
#attacks #began #being #cve-2026-33017: #flaw #hours #langflow #news #revealed. #the #vulnerability #within — News
© Bulletproof Servers. All rights reserved.