Lyrie
Actively Exploited
CVSS 9.8ACTIVELY EXPLOITED4 sources verified·1 min read
By Lyrie Threat Intelligence·5/21/2026

CRITICAL: CVE-2026-33017 actively exploited — langflow langflow

CVE: CVE-2026-33017

CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: CRITICAL

Status: ✅ Confirmed exploited in the wild (CISA KEV)

Affected

  • langflow langflow

Summary

Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the optional data parameter is supplied, the endpoint uses attacker-controlled flow data (containing arbitrary Python code in node definitions) instead of the stored flow data from the database. This code is passed to exec() with zero sandboxing, resulting in unauthenticated remote code execution. This is distinct from CVE-2025-3248, which fixed /api/v1/validate/code by adding authentication. The build_public_tmp endpoint is designed to be unauthenticated (for public flows) but incorrectly accepts attacker-supplied flow data containing arbitrary executable code. This issue has been fixed in version 1.9.0.

Verified Sources

References

  • https://github.com/advisories/GHSA-rvqx-wpfh-mfx7
  • https://github.com/langflow-ai/langflow/commit/73b6612e3ef25fdae0a752d75b0fabd47328d4f0
  • https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx
  • https://github.com/langflow-ai/langflow/releases/tag/1.8.2
  • https://medium.com/@aviral23/cve-2026-33017-how-i-found-an-unauthenticated-rce-in-langflow-by-reading-the-code-they-already-dc96cdce5896
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33017
  • https://www.sysdig.com/blog/cve-2026-33017-how-attackers-compromised-langflow-ai-pipelines-in-20-hours

_Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation._

Lyrie Verdict

Lyrie's autonomous detection layer catches active exploitation primitives at machine speed — closing the gap between disclosure and weaponization that traditional defense simply can't cover.

Validated sources

  1. [1]NVD
  2. [2]GitHub Advisory
  3. [3]MITRE
  4. [4]CISA KEV