CVE-2026-33017
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 8 apr
Vulnerabilità · 186 giorni fa
Tentativi di sfruttamento sono stati osservati entro 20 ore dalla pubblicazione dell'advisory. Fonti indicano esfiltrazione di chiavi e credenziali.
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 8 apr
4 fonti che coprono questa storia
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
Three LangChain flaws enable data theft across LLM apps, affecting millions of deployments, exposing secrets and files.
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33017 and CVE-2026-33634.
Critical Flaw in Langflow AI Platform Under Attack
Threats actors pounced on the vulnerability within hours of its disclosure, demonstrating that organizations have little time to address critical bugs.
CISA: New Langflow flaw actively exploited to hijack AI workflows
The Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are actively exploiting a critical vulnerability identified as CVE-2026-33017, which affects the Langflow framework for building AI agents.
Part of the PlainSec briefing for 2026-03-28