Vulnerabilities & Exploits · Web App Attack

Langflow Code-Injection Flaw Actively Exploited After Disclosure

Exploitation began within 24 hours of public disclosure and CISA added the issue to its Known Exploited Vulnerabilities catalog. The endpoint lets attacker-supplied Python code run during flow builds; versions 1.8.1 and earlier are affected.

4 sources · Mar 27

CVE-2026-33017

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Apr 8

Timeline

Sources

Part of the PlainSec briefing for 2026-03-27

Every edition of this story: Langflow Code-Injection Flaw Actively Exploited After Disclosure

More from today