Vulnerabilities & Exploits · Web App Attack
Langflow Code-Injection Flaw Actively Exploited After Disclosure Exploitation began within 24 hours of public disclosure and CISA added the issue to its Known Exploited Vulnerabilities catalog. The endpoint lets attacker-supplied Python code run during flow builds; versions 1.8.1 and earlier are affected.
4 sources · Mar 27
NVD KEV
Known exploited · CISA KEV
CISA federal remediation date Apr 8
Timeline Sources Mar 27 The Hacker News
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
Three LangChain flaws enable data theft across LLM apps, affecting millions of deployments, exposing secrets and files.
original Mar 27 Help Net Security
CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation - Help Net Security
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33017 and CVE-2026-33634.
original Mar 26 Dark Reading
Critical Flaw in Langflow AI Platform Under Attack
Threats actors pounced on the vulnerability within hours of its disclosure, demonstrating that organizations have little time to address critical bugs.
original Part of the PlainSec briefing for 2026-03-27
Every edition of this story: Langflow Code-Injection Flaw Actively Exploited After Disclosure
More from today
Vulnerabilities & Exploits · Web App Attack
Langflow Code-Injection Flaw Actively Exploited After Disclosure Exploitation began within 24 hours of public disclosure and CISA added the issue to its Known Exploited Vulnerabilities catalog. The endpoint lets attacker-supplied Python code run during flow builds; versions 1.8.1 and earlier are affected.
4 sources · Mar 27
NVD KEV
Known exploited · CISA KEV
CISA federal remediation date Apr 8
Timeline Sources Mar 27 The Hacker News
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
Three LangChain flaws enable data theft across LLM apps, affecting millions of deployments, exposing secrets and files.
original Mar 27 Help Net Security
CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation - Help Net Security
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33017 and CVE-2026-33634.
original Mar 26 Dark Reading
Critical Flaw in Langflow AI Platform Under Attack
Threats actors pounced on the vulnerability within hours of its disclosure, demonstrating that organizations have little time to address critical bugs.
original Part of the PlainSec briefing for 2026-03-27
Every edition of this story: Langflow Code-Injection Flaw Actively Exploited After Disclosure
More from today