Vulnerabilità ed exploit · Attacco ad app web
Langflow sfruttata entro 24 ore dopo divulgazione CVE-2026-33017 è una vulnerabilità di code injection che permette l'esecuzione di codice Python controllato dall'attaccante durante la build dei flow. CISA ha inserito la falla nel catalogo KEV; sono interessate le versioni 1.8.1 e precedenti.
4 fonti · 27 mar
NVD KEV
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 8 apr
Cronologia Fonti 27 mar The Hacker News
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
Three LangChain flaws enable data theft across LLM apps, affecting millions of deployments, exposing secrets and files.
originale 27 mar Help Net Security
CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation - Help Net Security
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33017 and CVE-2026-33634.
originale 26 mar Dark Reading
Critical Flaw in Langflow AI Platform Under Attack
Threats actors pounced on the vulnerability within hours of its disclosure, demonstrating that organizations have little time to address critical bugs.
originale Part of the PlainSec briefing for 2026-03-27
Every edition of this story: Langflow sfruttata entro 24 ore dopo divulgazione
Altro da oggi
Vulnerabilità ed exploit · Attacco ad app web
Langflow sfruttata entro 24 ore dopo divulgazione CVE-2026-33017 è una vulnerabilità di code injection che permette l'esecuzione di codice Python controllato dall'attaccante durante la build dei flow. CISA ha inserito la falla nel catalogo KEV; sono interessate le versioni 1.8.1 e precedenti.
4 fonti · 27 mar
NVD KEV
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 8 apr
Cronologia Fonti 27 mar The Hacker News
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
Three LangChain flaws enable data theft across LLM apps, affecting millions of deployments, exposing secrets and files.
originale 27 mar Help Net Security
CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation - Help Net Security
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33017 and CVE-2026-33634.
originale 26 mar Dark Reading
Critical Flaw in Langflow AI Platform Under Attack
Threats actors pounced on the vulnerability within hours of its disclosure, demonstrating that organizations have little time to address critical bugs.
originale Part of the PlainSec briefing for 2026-03-27
Every edition of this story: Langflow sfruttata entro 24 ore dopo divulgazione
Altro da oggi