Vulnerabilities & Exploits · Web App Attack

Langflow Flaw Enables Unauthenticated Remote Code Execution

Exploit achieved unauthenticated remote code execution roughly 20 hours after disclosure.

3 sources · Mar 20

CVE-2026-33017

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Apr 8

Timeline

Sources

Part of the PlainSec briefing for 2026-03-26

Every edition of this story: Langflow Flaw Enables Unauthenticated Remote Code Execution

More from today