CVE-2026-27966
CVSS 9.8 CRITICAL: langflow is a tool for building and deploying AI-powered agents and workflows. EPSS 34% (98th percentile).
Vulnerabilities & Exploits · Web App Attack
Metasploit now turns Langflow into a low-friction target for both verification and exploitation. The bigger shift is not the new module itself. It is the added check-method reasoning, which makes it easier to tell when a target is truly vulnerable and easier to reproduce the result at scale.
Rapid7’s weekly wrap-up adds an exploit module for CVE-2026-27966 in Langflow and an auxiliary module for CVE-2024-46987 in Camaleon CMS. It also adds improved check visibility, legacy SMB target handling, and updates to a PHP WebDAV upload exploit with Linux support and cleanup.
For defenders, the practical risk is that Langflow exposure is now easier to confirm and operationalize. That lowers the barrier for both internal validation and hostile use, especially where teams rely on version checks or noisy scans instead of direct verification.
1 source · Apr 24
CVSS 9.8 CRITICAL: langflow is a tool for building and deploying AI-powered agents and workflows. EPSS 34% (98th percentile).
CVSS 7.7 HIGH: camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. EPSS 15% (96th percentile).
Rapid7
Metasploit Wrap-Up 04/25/2026
The new content includes an auxiliary module for Camaleon CMS Directory Traversal (CVE-2024-46987), an exploit for Langflow RCE (CVE-2026-27966) due to a prompt injection vulnerability, an updated WebDAV PHP Upload exploit with Linux support and cleanup, and a new Linux Chmod payload for loongarch64 architectures.
originalPart of the PlainSec briefing for 2026-04-25
Every edition of this story: Metasploit Makes Langflow Exploitation Easy to Verify